Cisco Secure Email Gateway insufficient validation flaw (CVE-2026-76461)
Vulnerability
Summary
Hide ▲
Show ▼
Cisco Secure Email Gateway devices are exposed to CVE-2026-76461, an actively exploited email-parsing flaw that can let an unauthenticated remote attacker execute commands with root privileges. Cisco says the weakness affects both physical and virtual appliances and released fixes for 15.5 and earlier, 16.0, and 16.5. There are no workarounds beyond upgrading, and Cisco warned that exploitation can hide evidence on the device. CISA added the CVE to KEV and set a September 17, 2026 deadline for FCEB patching.
Timeline
-
15.09.2026 09:11 3 articles · 2h ago
Cisco warns CVE-2026-76461 is under active exploitation
Initial DisclosureCisco warned that CVE-2026-76461 in AsyncOS Software for Cisco Secure Email Gateway is under active exploitation and that a crafted email carrying malicious SQL can let an unauthenticated remote attacker execute arbitrary SQL statements and reach root-level command execution on Cisco Secure Email Gateway devices. Cisco listed fixed builds for 15.5 and earlier, 16.0, and 16.5, said there are no workarounds other than updating to the latest supported version, and advised reviewing mail_logs and running grep -i "COPY.*TO PROGRAM" against IronPort Text Mail Logs for suspicious activity.
Show sources
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution — thehackernews.com — 15.09.2026 09:11
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution — thehackernews.com — 15.09.2026 09:11
- Cisco patches Secure Email Gateway zero-day exploited in attacks — www.bleepingcomputer.com — 15.09.2026 10:31
-
15.09.2026 09:11 1 articles · 2h ago
CISA adds CVE-2026-76461 to KEV catalog and sets September 17, 2026 deadline
Legal Policy Action UpdateCISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog and required Federal Civilian Executive Branch agencies to apply the available patches by September 17, 2026. Cisco warned that successful exploitation can yield command execution with root privileges and that evidence of exploitation may be removed or hidden on the impacted device.
Show sources
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution — thehackernews.com — 15.09.2026 09:11