LmCast :: Stay tuned in

Cisco patches Secure Email Gateway zero-day exploited in attacks

Recorded: Sept. 15, 2026, 8 a.m.

Original Summarized

Cisco patches Secure Email Gateway zero-day exploited in attacks

News

Featured
Latest

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Homebrew 7.0.0 gets built-in GUI, better security controls

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

New Android malware encrypts files, steals data, and harasses victims

Cisco patches Secure Email Gateway zero-day exploited in attacks

Microsoft releases emergency Windows updates to fix RDS failures

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Homebrew 7.0.0 gets built-in GUI, better security controls

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCisco patches Secure Email Gateway zero-day exploited in attacks

Cisco patches Secure Email Gateway zero-day exploited in attacks

By Sergiu Gatlan

September 15, 2026
03:31 AM
0

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.
"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned in a Monday security advisory.
The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration.
Successful exploitation can allow unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system.
"This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," Cisco added. "A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system."
Cisco shared indicators of compromise and advised network defenders to look for suspicious SQL statements in each cluster device's mail_logs.
However, admins should also cross-check network and firewall logs for signs of suspicious activity (including uploads and downloads to and from external or malicious IP addresses) because attackers may remove evidence of exploitation.
Internet security watchdog Shadowserver currently tracks over 400 Cisco Secure Email Gateway appliances, but it provides no information on how many are honeypots or have already been secured against attacks.

Internet-exposed Cisco Secure Email Gateway appliances (Shadowserver)
The Cybersecurity and Infrastructure Security Agency (CISA) also added the CVE-2026-76461 flaw to its Known Exploited Vulnerabilities (KEV) Catalog on Monday, ordering federal agencies to patch their systems within three days, by September 17.
On Monday, Cisco addressed four other critical vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443) affecting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances regardless of configuration, but said it had no evidence they have also been exploited in the wild.
In January, the company also patched a maximum-severity Cisco AsyncOS flaw (CVE-2025-20393) exploited in zero-day attacks against SEG and SEWM devices since November 2025.
More recently, Cisco revealed that three separate ransomware and state-sponsored threat groups have exploited two recently patched Secure Firewall Management Center (FMC) flaws.
Since November 2021, CISA has flagged 98 Cisco vulnerabilities as actively exploited in attacks, including seven abused by ransomware gangs.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackersCritical Cisco bug lets hackers add root users on SEG devicesNew 'BlueMoon' kit exploited Windows and Chrome zero-day flawsCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksGoogle warns of new Chrome zero-day bug exploited in attacks

Actively Exploited
Cisco
Secure Email Gateway
Zero-Day

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Microsoft releases emergency Windows updates to fix RDS failures

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Sponsor Posts

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

Overdue a password health-check? Audit your Active Directory for free

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

Cisco recently issued a security advisory warning customers to patch a critical zero-day vulnerability in their Secure Email Gateway that threat actors have been actively exploiting. This vulnerability, tracked as CVE-2026-76461, resides in the email parsing logic within Cisco AsyncOS Software for Cisco Secure Email Gateway, affecting both virtual and physical appliances irrespective of device configuration. Successfully exploiting this flaw permits unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system. The vulnerability stems from insufficient validation in the email parsing logic, allowing an attacker to exploit it by sending a specially crafted email message containing malicious SQL statements through an affected device. This attack vector enables the execution of arbitrary SQL statements, which ultimately leads to command execution with root privileges on the system.

In response to the exploitation, Cisco advised network defenders to scrutinize each cluster device's mail_logs for any suspicious SQL statements. Furthermore, administrators should conduct comprehensive cross-checks of network and firewall logs to detect any signs of suspicious activity, including data uploads and downloads to or from external or malicious IP addresses, as attackers may attempt to remove evidence of exploitation. The Cybersecurity and Infrastructure Security Agency (CISA) elevated this vulnerability by adding CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) Catalog, mandating that federal agencies apply patches within three days. In addition to this specific flaw, Cisco addressed four other critical vulnerabilities, including CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443, which affect Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances regardless of their configuration, though Cisco reported no evidence of their current exploitation in the wild. The company has also noted past incidents, including the exploitation of a maximum-severity Cisco AsyncOS flaw (CVE-2025-20393) by zero-day attacks since November 2025, and the involvement of three separate ransomware and state-sponsored threat groups in exploiting recent Secure Firewall Management Center (FMC) flaws. Since November 2021, CISA has flagged 98 Cisco vulnerabilities as actively exploited in attacks, including seven leveraged by ransomware gangs.