Skip to main content
Emerging ThreatsMalware & Ransomware

Cisco Discloses Actively Exploited Zero-Day in Email Gateways

Rows of rack-mounted equipment in a network operations center with IT staff observing in the background.

CVE-2026-76461 is a critical, actively exploited zero-day that lets unauthenticated remote attackers execute commands as root on Cisco Secure Email Gateway appliances, authorities and independent researchers warn.

How CVE-2026-76461 works and why it matters

The vulnerability affects Cisco AsyncOS Software for Cisco Secure Email Gateway and can be reached by an attacker who simply sends an email through the appliance. Successful exploitation permits unauthenticated, remote command execution with root privileges — "In practical terms, that gives the attacker control of the gateway itself," Douglas McKee, director of vulnerability intelligence at Rapid7, told CyberScoop. The defect impacts both cloud-based and on-premises instances, according to Cisco.

Cisco’s detection, advisory, and mitigations

Cisco’s product security incident response team (PSIRT) said it became aware of active exploitation of the defect in September and disclosed and patched the vulnerability on Monday. The company said it "has conducted a thorough threat intelligence investigation on devices that belong to Cisco Secure Email Cloud" and that it "has directly contacted customers who own Cisco Secure Email Cloud devices where indicators of possible compromise were identified." Cisco added that it is "engaged in remediation and recovery operations" and that it "has already deployed mitigations that are within Cisco’s management."

Cisco also released indicators of compromise to help customers hunt for attempted exploitation, while warning that attackers who gain root-level access could remove or hide those traces.

CISA’s response and the KEV listing

The Cybersecurity and Infrastructure Security Agency added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog shortly after Cisco’s disclosure and patch guidance. Rapid7’s McKee said the tight timeline between Cisco’s advisory and CISA’s KEV addition “indicates the vulnerability deserves immediate attention.” He called the combination of factors — no authentication required, email as the attack vector, root-level command execution, and observed exploitation in the wild — "pretty ugly."

Observations from Rapid7 and VulnCheck

Researchers at Rapid7 and VulnCheck told CyberScoop they do not yet know the total number of organizations impacted by active exploitation, but both firms urged immediate patching and active hunting for signs of compromise. Spencer McIntyre, director of exploit development at VulnCheck, said the exploit could allow an attacker to maintain access to the email gateway and monitor communications.

McIntyre added: "Stealing or silently snooping on email comms is a common tactic for state-sponsored and other threat actors conducting espionage operations." He emphasized the operational difference between deployment types: "It’s going to be worse for organizations that have the appliance deployed on-premises. In this case, the attacker could pivot internally. If, however, organizations use a cloud instance, the compromised gateway is less likely to have significant access to internal organizational resources."

What this means for on-premises administrators, cloud customers, and security teams

  • On-premises administrators: Rapid7 and VulnCheck warn on-prem deployments face the greater risk of lateral movement and internal pivoting if a gateway is compromised; Cisco acknowledged multiple customers were likely compromised prior to disclosure.
  • Cloud customers and operators: Cisco said it has investigated devices that belong to Cisco Secure Email Cloud and has contacted customers where possible compromises were identified; VulnCheck noted cloud instances are less likely to grant an attacker broad internal access than on-prem appliances.
  • Security teams and incident responders: Cisco released indicators of compromise and said it is engaged in remediation and recovery operations, but it also cautioned that an attacker with root-level access could remove or hide traces, making active hunting and forensic validation essential.

The immediate fact is stark: an unauthenticated email can be the vector to full gateway control. Cisco has patched the flaw, CISA placed the CVE on the KEV catalog, and vendors and researchers have urged urgent remediation and hunting — yet Cisco did not publicly quantify how many customers were impacted prior to disclosure. The next practical step is simple and pressing for organizations that use Cisco Secure Email Gateway: apply Cisco’s patch guidance, consult the published indicators of compromise, and treat any history of unpatched exposure as a potential incident that warrants forensic review.

Source: https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/