Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that CVE-2026-76461 is being actively exploited in Cisco Secure Email Gateway, allowing unauthenticated attackers to run commands as root by sending a crafted email. The disclosure also follows reports of large-scale credential attacks against Fortinet VPN appliances, prompting CISA to add the Cisco flaw to its KEV catalog and require urgent patching. #CVE-2026-76461 #CiscoSecureEmailGateway #CISA #FortinetVPN

Keypoints

  • CVE-2026-76461 affects Cisco AsyncOS for Cisco Secure Email Gateway and is under active exploitation.
  • The flaw can let an unauthenticated remote attacker execute arbitrary commands with root privileges.
  • Cisco says the issue is caused by insufficient validation in the email parsing logic.
  • Fixes are available for affected AsyncOS versions, and no workaround exists besides updating.
  • CISA added CVE-2026-76461 to the KEV catalog, while Fortinet VPNs are also facing large-scale credential attacks.

Read More: https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html