Cisco patches critical zero-day vulnerability in Secure Email Gateway
Summary
Cisco has patched a critical zero-day vulnerability, identified as CVE-2026-76461, affecting its Secure Email Gateway appliances after it was exploited in the wild to gain root privileges. This vulnerability, which has a CVSS score of 9.8, allows attackers to execute arbitrary commands by sending specially crafted emails. Cisco's Product Security Incident Response Team (PSIRT) became aware of the exploitation in September 2026 and has since issued indicators of compromise. The Cybersecurity and Infrastructure Security Agency (CISA) has directed federal organizations to address this vulnerability by September 17, 2026, as part of their efforts to manage known risks, particularly amidst a landscape where state-sponsored and criminal actors are increasingly targeting email and firewall security systems.
Analysis
Categories
Related sources
- https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html
- https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-921
- https://www.cisco.com/site/us/en/products/security/index.html
- https://www.cisco.com/c/en/us/support/security/content-security-management-appliance/products-security-advisories-list.html
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
- https://www.runzero.com/blog/cisco-secure-email-gateway/
- https://gbhackers.com/cisa-adds-actively-exploited-cisco-unified-cm-flaws-to-kev-catalog/
- https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog
- https://cipherssecurity.com/kev/
- https://blogs.cisco.com/cisco-on-cisco
- https://www.hkcert.org/security-bulletin/cisco-products-multiple-vulnerabilities_20260915
- https://www.stocktitan.net/sec-filings/CSCO/10-k-cisco-systems-inc-files-annual-report-87999ad16e4d.html
- https://www.cisa.gov/resources-tools/resources/kev-catalog