CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers are using this flaw in real attacks. The flaw, known as CVE-2026-76461, impacts Cisco AsyncOS software on Cisco Secure Email Gateway devices. CVE-2026-76461 is a type of SQL injection flaw, listed as CWE-89.
It might let a remote attacker send special requests to a weak Cisco Secure Email Gateway device and run any commands on the system. Successful exploitation can give root-level access, allowing an attacker full control of the affected device. Cisco Secure Email Gateway is often used at the edge of business networks to check email traffic and stop harmful messages, spam, phishing, and malware.
Compromising this system could lead to big security flaws because it handles a lot of incoming and outgoing emails, including ones with important business information.
An attacker with root access could change email security rules, look at saved messages, make ways to stay hidden, stop security logs, or use the broken gateway to get into the bigger network.
Cisco Secure Email Gateway 0-Day Vulnerability Exploited
Security teams need to check if the appliance has communicated to unknown external systems or done surprising admin actions. CISA added the weakness to the KEV list on September 14, 2026, and told affected federal agencies to use vendor fixes by September 17, 2026.
The agency also labeled the issue as needing forensic assessment under Binding Operational Directive 26-04, showing the high risk tied to confirmed exploitation.
The listing does not say if the flaw has been used in ransomware attacks. But, weaknesses that allow remote command execution without authentication and with root access are very useful to attackers, especially if the product is on the internet.
Organizations using Cisco Secure Email Gateway need to find all open AsyncOS instances, check their software versions, and follow Cisco’s advice for fixes quickly.
Where mitigations are unavailable, CISA advises organizations to follow applicable BOD 26-04 guidance for cloud services or discontinue use of the affected product. Security teams should prioritize incident-response checks alongside remediation.
InfoSecBulletin Cybersecurity for mankind
