[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fC2ECop_UOgG_I0zrM96GwnGOhsmnFU2TgP6P__ryi8c":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"282b3cd7-26bf-4e47-97b0-6106581eef5c","Cisco patches Secure Email Gateway zero-day exploited in attacks","cisco-patches-secure-email-gateway-zero-day-exploited-in-attacks-96c09c","Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]","Cisco has released a patch for a critical zero-day vulnerability in its Secure Email Gateway that was actively exploited by threat actors. The flaw, CVE-2026-76461, allows unauthenticated attackers to execute arbitrary commands with root privileges by sending a crafted email containing malicious SQL statements. CISA has added this CVE to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch within three days.","Cisco patches Secure Email Gateway zero-day exploited in attacks.","Cisco patches Secure Email Gateway zero-day exploited in attacks By Sergiu Gatlan September 15, 2026 03:31 AM 0 Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. \"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability,\" the company warned in a Monday security advisory. The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration. Successful exploitation can allow unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system. \"This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,\" Cisco added. \"A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.\" Cisco shared indicators of compromise and advised network defenders to look for suspicious SQL statements in each cluster device's mail_logs. However, admins should also cross-check network and firewall logs for signs of suspicious activity (including uploads and downloads to and from external or malicious IP addresses) because attackers may remove evidence of exploitation. Internet security watchdog Shadowserver currently tracks over 400 Cisco Secure Email Gateway appliances, but it provides no information on how many are honeypots or have already been secured against attacks. Internet-exposed Cisco Secure Email Gateway appliances (Shadowserver) The Cybersecurity and Infrastructure Security Agency (CISA) also added the CVE-2026-76461 flaw to its Known Exploited Vulnerabilities (KEV) Catalog on Monday, ordering federal agencies to patch their systems within three days, by September 17. On Monday, Cisco addressed four other critical vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443) affecting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances regardless of configuration, but said it had no evidence they have also been exploited in the wild. In January, the company also patched a maximum-severity Cisco AsyncOS flaw (CVE-2025-20393) exploited in zero-day attacks against SEG and SEWM devices since November 2025. More recently, Cisco revealed that three separate ransomware and state-sponsored threat groups have exploited two recently patched Secure Firewall Management Center (FMC) flaws. Since November 2021, CISA has flagged 98 Cisco vulnerabilities as actively exploited in attacks, including seven abused by ransomware gangs. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackersCritical Cisco bug lets hackers add root users on SEG devicesNew 'BlueMoon' kit exploited Windows and Chrome zero-day flawsCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksGoogle warns of new Chrome zero-day bug exploited in attacks","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F08\u002F11\u002FCisco.jpg","2026-09-15T07:31:09+00:00","2026-09-15T08:00:14.956881+00:00",9,[18,21,23,26],{"name":19,"type":20},"Cisco Secure Email Gateway","product",{"name":22,"type":20},"Cisco AsyncOS Software",{"name":24,"type":25},"Cisco","vendor",{"name":27,"type":20},"Cisco Secure Firewall Management Center","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":28,"icon":30,"name":31,"slug":32},null,"Vulnerabilities","vulnerabilities",[34,39,44,49],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":40},{"id":41,"icon":30,"name":42,"slug":43},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":45},{"id":46,"icon":30,"name":47,"slug":48},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":50},{"id":51,"icon":30,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55,59,62,64,66,68],{"type":56,"value":57,"context":58},"cve","CVE-2026-76461","Cisco Secure Email Gateway zero-day vulnerability",{"type":56,"value":60,"context":61},"CVE-2026-76440","Other critical vulnerability affecting Secure Email Gateway",{"type":56,"value":63,"context":61},"CVE-2026-76441",{"type":56,"value":65,"context":61},"CVE-2026-20353",{"type":56,"value":67,"context":61},"CVE-2026-76443",{"type":56,"value":69,"context":70},"CVE-2025-20393","Previously exploited Cisco AsyncOS flaw"]