Cisco patches Secure Email Gateway zero-day exploited in attacks
Recorded: Sept. 15, 2026, 8 a.m.
| Original | Summarized |
Cisco patches Secure Email Gateway zero-day exploited in attacks News Featured Hackers hijack HBO Max Reddit account to push malware in ClickFix ads Homebrew 7.0.0 gets built-in GUI, better security controls Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent New Android malware encrypts files, steals data, and harasses victims Cisco patches Secure Email Gateway zero-day exploited in attacks Microsoft releases emergency Windows updates to fix RDS failures Japan's Digital Agency says VPN flaw exposed 246,000 personnel records Homebrew 7.0.0 gets built-in GUI, better security controls Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityCisco patches Secure Email Gateway zero-day exploited in attacks Cisco patches Secure Email Gateway zero-day exploited in attacks By Sergiu Gatlan September 15, 2026 Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. Internet-exposed Cisco Secure Email Gateway appliances (Shadowserver) Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Actively Exploited Sergiu Gatlan Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Microsoft releases emergency Windows updates to fix RDS failures Hackers exploit Tencent app flaw to deploy GrayRabbit malware Sponsor Posts EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday. Overdue a password health-check? Audit your Active Directory for free Patch automation needs more than speed. Action1 brings control into every stage of deployment. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
Cisco recently issued a security advisory warning customers to patch a critical zero-day vulnerability in their Secure Email Gateway that threat actors have been actively exploiting. This vulnerability, tracked as CVE-2026-76461, resides in the email parsing logic within Cisco AsyncOS Software for Cisco Secure Email Gateway, affecting both virtual and physical appliances irrespective of device configuration. Successfully exploiting this flaw permits unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system. The vulnerability stems from insufficient validation in the email parsing logic, allowing an attacker to exploit it by sending a specially crafted email message containing malicious SQL statements through an affected device. This attack vector enables the execution of arbitrary SQL statements, which ultimately leads to command execution with root privileges on the system. In response to the exploitation, Cisco advised network defenders to scrutinize each cluster device's mail_logs for any suspicious SQL statements. Furthermore, administrators should conduct comprehensive cross-checks of network and firewall logs to detect any signs of suspicious activity, including data uploads and downloads to or from external or malicious IP addresses, as attackers may attempt to remove evidence of exploitation. The Cybersecurity and Infrastructure Security Agency (CISA) elevated this vulnerability by adding CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) Catalog, mandating that federal agencies apply patches within three days. In addition to this specific flaw, Cisco addressed four other critical vulnerabilities, including CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443, which affect Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances regardless of their configuration, though Cisco reported no evidence of their current exploitation in the wild. The company has also noted past incidents, including the exploitation of a maximum-severity Cisco AsyncOS flaw (CVE-2025-20393) by zero-day attacks since November 2025, and the involvement of three separate ransomware and state-sponsored threat groups in exploiting recent Secure Firewall Management Center (FMC) flaws. Since November 2021, CISA has flagged 98 Cisco vulnerabilities as actively exploited in attacks, including seven leveraged by ransomware gangs. |