Cisco patches Secure Email Gateway zero-day that gives root through a crafted email
CVE-2026-76461 in AsyncOS email parsing is under active exploitation and affects every virtual and physical appliance regardless of configuration.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
Cisco has warned customers to patch a critical zero-day in Secure Email Gateway that attackers are already exploiting. The flaw, tracked as CVE-2026-76461, sits in the email parsing logic of Cisco AsyncOS Software. It affects virtual and physical appliances regardless of how the device is configured. An unauthenticated remote attacker can send a crafted email containing malicious SQL statements through an affected device. Cisco says the insufficient validation lets those statements execute, which leads to command execution with root privileges on the underlying operating system. The company's product security incident response team said it became aware of active exploitation in September 2026 and published the advisory on Monday. Cisco has shared indicators of compromise. It advises defenders to look for suspicious SQL statements in the mail logs of each cluster device. Administrators should also cross-check network and firewall logs for other signs of intrusion, including uploads and downloads to or from external or malicious addresses. Email gateways sit at the network edge and handle inbound traffic from anyone on the internet, so an exploit that needs only a single message is a serious exposure for every organization running the product. Because exploitation predates the patch, affected teams should treat patching and log review as equally urgent.
Sources
- BleepingComputerCisco patches Secure Email Gateway zero-day exploited in attacks