Skip to main content

Tag: cve 2026 76461

2 articles

Secure Email Gateway device on a rack in a dimly lit server room with IT staff member working in the background.

Cisco Discloses Zero-Day Exploited in Secure Email Gateway Attacks

Cisco has warned of a zero-day flaw in its Secure Email Gateway that allows attackers to run commands as root, prompting federal agencies to patch the vulnerability within just three days. This critical defect, tracked as CVE-2026-76461, lets hackers execute arbitrary commands with root privileges, putting systems at risk.

Analyst 207
Cisco Secure Email Gateway device centered on a network operations rack in a data center.

Cisco Email Gateway Flaw Exploited, Enables Root Command Execution

A critical Cisco email gateway flaw, CVE-2026-76461, with a near-perfect CVSS score of 9.8, is being actively exploited in the wild, allowing attackers to send a single crafted email and gain root command execution on vulnerable devices. This severe vulnerability stems from insufficient validation in AsyncOS email parsing, making it a pressing concern for Cisco Secure Email Gateway users.

Analyst 207