ZeroHour
Story · 13 sources · 15 articlesfirst updated ()

Cisco Warns of Actively Exploited Zero-Day CVE-2026-76461 in Secure Email Gateway: Crafted Email Yields Unauthenticated Root Command Execution

What's new: The final report (Security Affairs, 20:46 UTC) confirms CISA's KEV listing and federal September 17, 2026 remediation deadline but cites BOD 22-01, conflicting with Cyber Security News' earlier citation of BOD 26-04 for the same enforcement action. No other substantive new facts emerged after the previous summary; later reports (The Register, CSO Online) had already added the Shadowserver count…
Merged summary · glm-5.3 · rewritten as coverage arrives

CVSS 9.8 unauthenticated SQL-injection zero-day CVE-2026-76461 in Cisco Secure Email Gateway AsyncOS is being exploited in the wild, letting a single crafted email deliver root command execution; CISA added it to the KEV catalog with a September 17, 2026…

Cisco PSIRT disclosed CVE-2026-76461, a critical CVSS 9.8 unauthenticated SQL injection (CWE-89) in AsyncOS for Cisco Secure Email Gateway caused by insufficient validation in email-parsing logic. A remote, unauthenticated attacker can execute arbitrary SQL statements — and thereby arbitrary OS commands with root privileges — simply by sending a crafted email through a vulnerable gateway; no authentication or user interaction is required. The flaw affects physical appliances, virtual deployments, and Cisco Secure Email Cloud regardless of configuration, and no workarounds exist. Cisco became aware of active exploitation in September 2026, and exploitation occurred before disclosure; some Secure Email Cloud customers showed indicators of compromise, with Cisco deploying server-side remediations (The Register reports all cloud devices were upgraded to AsyncOS 16.5.0-780) and directly contacting affected cloud customers, while on-premises admins must patch themselves. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14, 2026 — the disclosure day — and federal civilian agencies must apply vendor mitigations by September 17, 2026 (the governing directive is reported inconsistently: Cyber Security News cites BOD 26-04 with mandatory forensic triage, while Security Affairs cites BOD 22-01); unpatched internet-facing appliances should be treated as potentially compromised, and Shadowserver counted more than 400 internet-exposed appliances. CSO Online notes this is the second Secure Email Gateway flaw ever added to KEV, after CVE-2025-20393. A compromised gateway could let attackers alter email security policies, access stored messages, silently monitor email, disable logging, and pivot into enterprise networks (Rapid7 and VulnCheck warn of silent monitoring and internal pivoting); because root-level attackers may purge or tamper with logs, Cisco advises reviewing external firewall/network logs, taking forensic snapshots, rebuilding appliances, and rotating credentials. Detection guidance: grep mail_logs on each clustered device for suspicious SQL statements such as 'COPY.*TO PROGRAM'. Fixed releases are consistently reported as AsyncOS 16.5.0-780, but sources disagree on the branch versions: 16.0.4-3021 and 15.5.5-0141 (Cyber Security News, CSO Online) versus 16.0.4-302 and 15.5.5-014 (The Register, Rapid7, The Hacker News mixes both). Rapid7 reports no public PoC and no threat-actor attribution. The Hacker News separately notes…

  • CVE-2026-76461 is a CVSS 9.8 unauthenticated SQL injection (CWE-89) in Cisco AsyncOS for Secure Email Gateway caused by insufficient email-parsing validation.
  • A crafted email containing malicious SQL statements gives a remote, unauthenticated attacker arbitrary command execution with root privileges; no workarounds exist.
  • Actively exploited in the wild before disclosure; Cisco PSIRT became aware of exploitation in September 2026.
  • CISA added the flaw to its KEV catalog on September 14, 2026, requiring FCEB agencies to remediate by September 17, 2026 — sources conflict on the directive (BOD 26-04 per Cyber Security News vs. BOD 22-01 per Security Affairs).
  • Fixed in AsyncOS 16.5.0-780 plus branch releases; sources disagree on exact build numbers: 16.0.4-3021/15.5.5-0141 vs. 16.0.4-302/15.5.5-014.
  • Affects physical appliances, virtual deployments, and Cisco Secure Email Cloud regardless of configuration; Cisco applied server-side cloud fixes (all cloud devices reportedly upgraded to 16.5.0-780) and contacted affected cloud customers…
  • Shadowserver counted more than 400 internet-exposed Cisco Secure Email Gateway appliances.
  • Detection: grep mail_logs on each clustered device for suspicious SQL statements such as 'COPY.*TO PROGRAM'; root-level attackers may tamper with logs, so external firewall/network logs, forensic snapshots, rebuilds, and credential…

Coverage timeline

  1. · 1d ago
    CISA Advisories· 75
    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA added CVE-2026-76461, an actively exploited SQL injection in Cisco Secure Email Gateway, to the KEV catalog.

  2. · 1d ago
    Canadian Centre for Cyber Security· 75
    Cisco security advisory (AV26-921)

    Canadian Cyber Centre warns actively exploited Cisco Secure Email Gateway SQL injection CVE-2026-76461 was added to CISA's KEV database.

  3. · 17h ago
    Cyber Security News· 88
    Hackers Exploit Critical Cisco Secure Email Gateway Vulnerability in the Wild to Run Malicious Code

    Cisco warns attackers actively exploit zero-day CVE-2026-76461 in Secure Email Gateway, gaining unauthenticated root command execution via crafted emails.

  4. · 16h ago
    GBHackers· 78
    Hackers Exploit Critical Cisco Secure Email Gateway Flaw to Execute Commands as Root

    Cisco patched critical unauthenticated SQL injection CVE-2026-76461 (CVSS 9.8) in Secure Email Gateway enabling root command execution, with malicious activity already detected.

  5. · 16h ago
  6. · 15h ago
    The Hacker News· 92
    Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

    Cisco warns CVE-2026-76461 in Secure Email Gateway AsyncOS is actively exploited, letting unauthenticated attackers run root commands via crafted emails.

  7. · 10h ago
    Help Net Security· 85
    Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

    Actively exploited zero-day SQL injection (CVE-2026-76461) in Cisco Secure Email Gateway allows unauthenticated root command execution; CISA ordered federal remediation by September 17.

  8. · 9h ago
    Rapid7 Blog· 92
    CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

    Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) enables unauthenticated root command execution via crafted email; CISA added it to KEV.

  9. · 8h ago
    Security Affairs· 93
    Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day

    Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) is actively exploited for root command execution; CISA added it to KEV.

  10. · 7h ago
    Qualys ThreatPROTECT· 82
    Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)

    Cisco Secure Email Gateway flaw CVE-2026-76461 enables root command execution via crafted email SQL injection and is actively exploited, added to CISA KEV.

  11. · 6h ago
    Cyber Security News· 92
    CISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks

    CISA added actively exploited Cisco Secure Email Gateway SQL injection flaw CVE-2026-76461 to its KEV catalog, enabling unauthenticated root command execution.

  12. · 5h ago
    CyberScoop· 92
    Cisco warns customers of actively exploited zero-day in email gateways

    Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 allows unauthenticated root command execution; CISA added it to KEV.

  13. · 5h ago
    The Register · Security· 92
    Cisco email security boxes can be rooted by... an email

    Attackers actively exploit critical Cisco Secure Email Gateway flaw CVE-2026-76461, turning a malicious email into unauthenticated root access.

  14. · 1h ago
    CSO Online· 92
    Critical Cisco Secure Email Gateway zero-day gives attackers root access

    Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 lets crafted emails trigger SQL injection and root command execution; CISA added it to KEV.

  15. · 36m ago
    Security Affairs· 85
    U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

    CISA added actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) to KEV; federal agencies must patch by September 17, 2026.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20393
Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands

CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined.

Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown.

10.030% KEV
  • Cisco Secure Email Gateway / Secure Email
  • Cisco AsyncOS Software
  • Cisco Web Manager appliance
largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished)
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20316
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).

Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29.

5.311% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC)
largeplausibly tens of thousands of FMC deployments worldwide (no published install base)
CVE-2026-76461
Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway

Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent.

Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts.

9.82% KEV PoC ×2
  • Cisco Secure Email Gateway (Cisco AsyncOS Software)
large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances)