Back to advisories

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.

CRITICALAdvisorySep 16, 2026
Action required
Immediately patch all Cisco Secure Email Gateway instances to the latest patched version. If patching cannot be completed within 24 hours, isolate affected gateways from production email flow.
Affected products
Cisco Secure Email GatewayCisco AsyncOS SoftwareCiscoCisco Secure Firewall Management Center