Cisco warned customers to urgently patch CVE-2026-76461, a critical zero-day in Cisco Secure Email Gateway that is being actively exploited and can let unauthenticated attackers run commands as root. CISA added the flaw to its KEV Catalog and Cisco also disclosed additional critical vulnerabilities affecting Secure Email Gateway and Secure Email and Web Manager appliances. #CVE-2026-76461 #CiscoSecureEmailGateway #CISA #CiscoAsyncOS
Keypoints
- Cisco confirmed active exploitation of CVE-2026-76461 in Secure Email Gateway appliances.
- The flaw can allow remote, unauthenticated command execution with root privileges.
- Cisco urged defenders to inspect mail_logs for suspicious SQL statements and review network logs.
- CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog and ordered fast patching.
- Cisco also fixed four other critical flaws in Secure Email Gateway and Secure Email and Web Manager devices.