Cisco Email Gateways Under Active Attack: Patch Now
Cisco has warned customers of a critical zero-day vulnerability, CVE-2026-76461, in its Secure Email Gateway product that is being actively exploited by attackers of unknown origin. The flaw allows unauthenticated, remote attackers to execute commands with root privileges, effectively giving them full control of the gateway. Cisco's security team became aware of active exploitation in September, before the company publicly disclosed and patched the issue on Monday.
Cisco has not disclosed how many organisations have been affected, but it has confirmed that multiple customers were likely compromised before the public disclosure. The company says it has directly contacted Cisco Secure Email Cloud customers where signs of possible compromise were found, and is working on remediation and recovery. The US Cybersecurity and Infrastructure Security Agency (CISA) quickly added the vulnerability to its Known Exploited Vulnerabilities catalog following Cisco's advisory.
Security researchers say the combination of factors makes this an especially serious issue: no authentication is needed, attackers can trigger the flaw simply by sending an email through the appliance, and successful exploitation grants root-level access. Both cloud-based and on-premises versions of the product are affected.