Cisco warns customers of actively exploited zero-day in email gateways

Cisco warns customers of actively exploited zero-day in email gateways
Attackers are exploiting CVE-2026-76461, a critical zero-day in Cisco Secure Email Gateway that allows unauthenticated remote command execution with root privileges. Cisco says it has seen active exploitation and has contacted affected cloud customers, while CISA quickly added the flaw to its Known Exploited Vulnerabilities catalog. #Cisco #CVE-2026-76461 #CiscoSecureEmailGateway #CiscoAsyncOS #CISA

Keypoints

  • CVE-2026-76461 is a critical zero-day in Cisco Secure Email Gateway.
  • The flaw allows unauthenticated remote attackers to execute commands as root.
  • Cisco confirmed active exploitation before public disclosure and patching.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
  • Rapid7 and VulnCheck urged customers to patch quickly and hunt for compromise.

Read More: https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/