[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQ6PuOsyXZ_IlVPILZru3a4YH5yk3x7zWeUJVZVdnWz8":3},{"article":4,"iocs":60},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"78411793-095d-4364-9264-06ad57747d86","Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation","root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation-510a70","An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek.","Cisco has issued a warning about a critical zero-day vulnerability, CVE-2026-76461, affecting its Secure Email Gateway appliances. This flaw allows unauthenticated attackers to execute arbitrary commands with root privileges on the underlying OS by sending specially crafted emails. The vulnerability has been actively exploited in the wild since at least September 2026, and CISA has added it to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch it by September 17.","Cisco Secure Email Gateway zero-day RCE vulnerability CVE-2026-76461 actively exploited.","Cisco warned customers on Monday that a zero-day vulnerability affecting Secure Email Gateway appliances has been exploited in the wild. The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco describes it as an email parsing issue in AsyncOS software that can be exploited remotely and without authentication to execute arbitrary commands on the underlying operating system with root privileges. The tech giant explained that the critical flaw can be exploited to execute malicious SQL statements by sending them to the targeted user inside a specially crafted email. Cisco said its PSIRT became aware of the exploitation of CVE-2026-76461 in September 2026, but it has not shared details on attacks involving the zero-day. It’s also unclear who is behind the attacks. The company has released indicators of compromise (IoCs), but noted that because threat actors can obtain root privileges on a device, they can remove or hide IoCs to cover their tracks. The security hole affects both the physical and virtual versions of Secure Email Gateway in any configuration. Secure Email and Web Manager and Secure Web Appliance are not impacted.Advertisement. Scroll to continue reading. The cybersecurity agency CISA added CVE-2026-76461 to its KEV catalog on Monday and instructed federal organizations to address it by September 17. This is only the second Cisco Secure Email Gateway vulnerability in the KEV list, after CVE-2025-20393, which China-linked threat actors started exploiting in late 2025. CVE-2026-76461 is one of several vulnerabilities Cisco discovered internally in its Secure Email Gateway and Secure Email and Web Manager products. News of CVE-2026-76461’s exploitation comes just days after Cisco and CISA warned organizations about attacks leveraging CVE-2026-20079, a Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. Cisco warned that CVE-2026-20079 and another FMC weakness tracked as CVE-2026-20316 have been exploited by both Russian state-sponsored hackers and profit-driven cybercriminals. Related: Three JFrog Artifactory Flaws Exploited for Backdoor Deployment Related: BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days Related: ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks Related: Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Trezor Says 347,000 Users Received Phishing Emails After Brevo HackUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonAnthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionCybersecurity M&A Roundup: 33 Deals Announced in August 2026Widened Scan Turns Up Fourth Rogue Claude Cyber IncidentOrganizations Warned of Cisco Secure FMC ExploitationRockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsAnthropic Details Response to Security Incidents, Unveils Enterprise Safeguards Latest News Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI DevelopmentNew Warnings About the Risks of AI to Humanity Revive a Long-Running DebatePersonal, Financial Info Exposed in Revolut Data BreachThe Race to Control AI and Protect What Makes Us HumanChinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code ExecutionCISOs Race to Control AI Agents Without Destroying Their ValueTelus Warns Customers of Account BreachesThree JFrog Artifactory Flaws Exploited for Backdoor Deployment Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Froot-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F07\u002FCisco-switches-network.jpeg","2026-09-15T05:18:51+00:00","2026-09-15T06:00:14.190577+00:00",9,[18,21,24,27,30,32],{"name":19,"type":20},"Secure Email Gateway","product",{"name":22,"type":23},"Cisco","vendor",{"name":25,"type":26},"AsyncOS","technology",{"name":28,"type":29},"China-linked threat actors","threat_actor",{"name":31,"type":29},"Russian state-sponsored hackers",{"name":33,"type":20},"Secure Firewall Management Center","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":34,"icon":36,"name":37,"slug":38},null,"Vulnerabilities","vulnerabilities",[40,45,50,55],{"category":41},{"id":42,"icon":36,"name":43,"slug":44},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":46},{"id":47,"icon":36,"name":48,"slug":49},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":51},{"id":52,"icon":36,"name":53,"slug":54},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":56},{"id":57,"icon":36,"name":58,"slug":59},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[61,65,68,71],{"type":62,"value":63,"context":64},"cve","CVE-2026-76461","Root RCE zero-day in Cisco Secure Email Gateway",{"type":62,"value":66,"context":67},"CVE-2025-20393","Previous Cisco Secure Email Gateway vulnerability exploited by China-linked actors",{"type":62,"value":69,"context":70},"CVE-2026-20079","Cisco Secure Firewall Management Center vulnerability exploited by Russian state-sponsored hackers and cybercriminals",{"type":62,"value":72,"context":70},"CVE-2026-20316"]