Back to advisories

Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabilities catalog.

CRITICALAdvisorySep 16, 2026
Action required
Immediately identify all Cisco Secure Email Gateway instances in your environment and patch to the latest available version. If you cannot patch immediately, isolate affected systems and conduct forensic analysis for signs of unauthorized root access or lateral movement.
Affected products
Secure Email GatewayCisco