ZeroHour
BleepingComputerpublished ()ingested Sergiu Gatlan

Cisco patches Secure Email Gateway zero-day exploited in attacks

AI summary · glm-5.3

Cisco patches actively exploited Secure Email Gateway zero-day CVE-2026-76461 enabling unauthenticated root command execution; CISA adds it to KEV.

Cisco disclosed that a critical zero-day (CVE-2026-76461) in the email parsing logic of AsyncOS for Secure Email Gateway is being actively exploited, allowing unauthenticated remote attackers to execute arbitrary SQL statements that lead to root-level command execution on virtual and physical appliances. CISA added the flaw to its KEV catalog and ordered federal agencies to patch within three days, by September 17. Cisco also patched four other critical SEG/SEWM vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443) with no evidence of exploitation, and shared IOCs including suspicious SQL statements in mail_logs.

  • CVE-2026-76461 is actively exploited as a zero-day in Cisco Secure Email Gateway.
  • Unauthenticated attackers can gain root command execution via crafted email with SQL statements.
  • CISA KEV listing requires federal patching by September 17.
  • Shadowserver tracks 400+ internet-exposed Secure Email Gateway appliances.
  • Four additional critical SEG/SEWM flaws patched with no observed exploitation.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20393
Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands

CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined.

Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown.

10.030% KEV
  • Cisco Secure Email Gateway / Secure Email
  • Cisco AsyncOS Software
  • Cisco Web Manager appliance
largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished)
CVE-2026-20353
+3 in the same advisory: …76440 …76441 …76443
Critical Unauthenticated Flaws in Cisco Secure Email Gateway & Email/Web Manager

CVE-2026-20353 bundles multiple internally discovered vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, grouped under the CWE-664 pillar ('improper control of a resource through its lifetime'). Cisco has not published technical detail on the individual flaws, but the maximum CVSS 3.1 score of 9.8 (network vector, low complexity, no privileges or user interaction required) indicates that at least one of the grouped issues is remotely exploitable without authentication with high impact on confidentiality, integrity, and availability. Successful exploitation could allow an unauthenticated attacker to fully compromise an affected email gateway or management appliance, which sit in a privileged position on the mail path and hold quarantine stores, message logs, and configuration data. The flaws were found through Cisco's proactive internal review and are addressed in software hardening releases rather than in response to observed attacks. No public proof-of-concept exists and the CVE is not in the CISA Known Exploited Vulnerabilities catalog as of this writing.

Do: Upgrade Cisco Secure Email Gateway and Secure Email and Web Manager to the fixed software releases listed in the Cisco PSIRT advisory for CVE-2026-20353 — the fixed versions are not enumerated in the summary data, so verify against Cisco's advisory directly. Restrict management and web interface access to trusted internal networks or VPN, since these appliances are commonly exposed at the network edge. Review logs for anomalous behavior on the management interface and confirm quarantine data and configuration integrity after patching.

9.8
  • Cisco Secure Email Gateway (formerly Email Security Appliance / ESA)
  • Cisco Secure Email and Web Manager (formerly Security Management Appliance / SMA)
moderateon the order of thousands to low tens of thousands of internet-reachable appliances, with a larger population deployed internally (clearly an estimate)
CVE-2026-76461
Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway

Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent.

Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts.

9.82% KEV PoC ×2
  • Cisco Secure Email Gateway (Cisco AsyncOS Software)
large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances)
Full article439 words · extracted from bleepingcomputer.com · click to collapse

Cisco

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.

"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned in a Monday security advisory.

The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration.

Successful exploitation can allow unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system.

"This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," Cisco added. "A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system."

Cisco shared indicators of compromise and advised network defenders to look for suspicious SQL statements in each cluster device's mail_logs.

However, admins should also cross-check network and firewall logs for signs of suspicious activity (including uploads and downloads to and from external or malicious IP addresses) because attackers may remove evidence of exploitation.

Internet security watchdog Shadowserver currently tracks over 400 Cisco Secure Email Gateway appliances, but it provides no information on how many are honeypots or have already been secured against attacks.

Internet-exposed Cisco Secure Email Gateway appliances
Internet-exposed Cisco Secure Email Gateway appliances (Shadowserver)

The Cybersecurity and Infrastructure Security Agency (CISA) also added the CVE-2026-76461 flaw to its Known Exploited Vulnerabilities (KEV) Catalog on Monday, ordering federal agencies to patch their systems within three days, by September 17.

On Monday, Cisco addressed four other critical vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443) affecting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances regardless of configuration, but said it had no evidence they have also been exploited in the wild.

In January, the company also patched a maximum-severity Cisco AsyncOS flaw (CVE-2025-20393) exploited in zero-day attacks against SEG and SEWM devices since November 2025.

More recently, Cisco revealed that three separate ransomware and state-sponsored threat groups have exploited two recently patched Secure Firewall Management Center (FMC) flaws.

Since November 2021, CISA has flagged 98 Cisco vulnerabilities as actively exploited in attacks, including seven abused by ransomware gangs.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/