Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Cisco warned that CVE-2026-76461, a critical zero-day in Secure Email Gateway appliances, is being actively exploited in the wild and can let attackers run commands as root through a specially crafted email. CISA has added the flaw to its KEV catalog and ordered federal agencies to patch it, while Cisco released IoCs but noted attackers may hide evidence after gaining root access. #Cisco #CVE-2026-76461 #SecureEmailGateway #CISA #KEV

Keypoints

  • CVE-2026-76461 is a zero-day affecting Cisco Secure Email Gateway appliances.
  • The flaw has a CVSS score of 9.8 and allows remote, unauthenticated code execution.
  • Attackers can abuse a specially crafted email to execute malicious SQL statements.
  • Cisco confirmed exploitation began in September 2026 but has not identified the attackers.
  • CISA added the vulnerability to its KEV catalog and set a September 17 deadline for federal agencies.

Read More: https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/