Cisco patches critical zero-day vulnerability in Secure Email Gateway

Summary

Cisco has patched a critical zero-day vulnerability, identified as CVE-2026-76461, affecting its Secure Email Gateway appliances after it was exploited in the wild to gain root privileges. This vulnerability, which has a CVSS score of 9.8, allows attackers to execute arbitrary commands by sending specially crafted emails. Cisco's Product Security Incident Response Team (PSIRT) became aware of the exploitation in September 2026 and has since issued indicators of compromise. The Cybersecurity and Infrastructure Security Agency (CISA) has directed federal organizations to address this vulnerability by September 17, 2026, as part of their efforts to manage known risks, particularly amidst a landscape where state-sponsored and criminal actors are increasingly targeting email and firewall security systems.

Analysis

CISA: CISA is the United States Cybersecurity and Infrastructure Security Agency responsible for protecting critical infrastructure and coordinating national cyber defense efforts. On September 14, 2026, CISA added the Cisco Secure Email Gateway zero-day vulnerability to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate it promptly. This action underscores the agency's role in prioritizing high-risk, actively exploited flaws for rapid mitigation across government systems. Cisco: Cisco is a major technology company specializing in networking, security, and digital infrastructure solutions, including email security appliances. In September 2026, Cisco disclosed and patched a critical unauthenticated remote code execution vulnerability in its Secure Email Gateway product that was under active exploitation. The company released software updates and indicators of compromise while noting the flaw's potential for root-level access on both physical and virtual deployments. Federal Directive: CISA required federal organizations to address the exploited Cisco vulnerability by September 17, 2026, as part of its ongoing efforts to manage known exploited risks in government environments. Security Landscape: This Cisco issue follows recent warnings about other exploited flaws in the company's products, highlighting continued focus on email and firewall security appliances amid state-sponsored and criminal threats. Vulnerability Disclosure: Cisco publicly detailed active exploitation of a critical SQL injection flaw in its Secure Email Gateway in mid-September 2026, issuing patches and guidance for affected customers.

Categories

tech

Related sources

View Original Tweet