The news
Cisco Systems (CSCO) warned on September 14 of a Cisco Secure Email Gateway zero-day, CVE-2026-76461, that attackers are already exploiting. The flaw lets an unauthenticated attacker send a crafted email that can lead to commands running as root on the appliance.
In its advisory, Cisco said its Product Security Incident Response Team (PSIRT) became aware of active exploitation in September 2026. The company rated the flaw 9.8 out of 10 on the Common Vulnerability Scoring System and said it affects both physical and virtual Secure Email Gateway appliances regardless of configuration. There is no workaround.
According to Cisco, the flaw sits in the email parsing of its AsyncOS software and allows a remote attacker to execute arbitrary SQL statements through a malicious email message, which can lead to root-level command execution on the underlying operating system. Cisco lists Secure Email and Web Manager and Secure Web Appliance as not affected.
Cisco published fixed releases for three software trains: 15.5.5-014 for release 15.5 and earlier, 16.0.4-302 for release 16.0 and 16.5.0-780 for release 16.5. For virtual appliances where exploitation is suspected, the advisory recommends deploying a new instance on fixed software, rebuilding the configuration, and renewing credentials and cryptographic material rather than simply upgrading in place. Owners of suspect physical appliances should contact Cisco's Technical Assistance Center (TAC) and leave remote access enabled for the investigation. Cisco also tells administrators to search the gateway's mail_logs for suspicious SQL statements and to check network and firewall logs outside the device for unexpected transfers.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on September 14 with a remediation deadline of September 17 for federal civilian agencies. Cisco has not said who is behind the attacks or how many customers were hit. Cisco warns that attackers with root may erase or conceal evidence of the intrusion. SecurityWeek noted that this is the second Secure Email Gateway flaw on CISA's list, after CVE-2025-20393, which China-linked actors exploited in late 2025.
The numbers
- CVSS severity score
- 9.8 / 10
- Advisory published
- Sept 14, 2026
- CISA federal patch deadline
- Sept 17, 2026
- Workarounds available
- None
Why CEOs should care
For CISOs, the email gateway sits exactly where attackers want to be: it accepts messages from anyone on the internet and it sees every inbound email. A flaw that is triggered by a message, not a login, means exposure is universal for affected versions. Confirm which release each gateway runs, patch to Cisco's fixed builds, run the mail_logs check and treat any unit that cannot be ruled clean as compromised: rebuild virtual ones, call Cisco TAC for physical ones. Rotating credentials and certificates is the step easiest to skip under time pressure.
For CFOs and IT leaders, recovery is not free. Budget for emergency change windows, clean replacement images for any compromised virtual units, time with Cisco support for physical ones, and the staff time to reissue certificates and keys that the gateway held. Ask whether your managed security provider's contract covers incident rebuilds of appliances it operates, and how quickly it can prove a device is clean.
For boards, the question is structural: how many security appliances does the company run that accept unauthenticated internet traffic, and who tracks exploited flaws in them? CISA gave agencies three days on this one. Ask management whether your own patch policy can meet a three-day window for internet-facing security gear.
The bigger picture
The Cisco bug is part of a broader September run against the security and networking products companies rely on for protection. CISA's catalog also added a Cisco Firewall Management Center authentication bypass on September 9 and a Cisco Identity Services Engine flaw on September 16, alongside exploited bugs in Citrix NetScaler, Fortinet and MikroTik gear. In our view, that is no accident: these devices sit at the network edge, open to the internet, and as this case shows, one flaw can hand an attacker root.
Vendors face new obligations too. Since September 11, the European Union's Cyber Resilience Act has required manufacturers of products with digital elements to send an early warning within 24 hours of becoming aware of an actively exploited vulnerability, with a fuller notification due within 72 hours, according to the European Commission.
What’s next
The advisory already lists indicators of compromise, but not who is behind the attacks. Watch for Cisco updates with attribution, and for incident response firms to publish findings on who exploited the flaw before disclosure. Organizations that find evidence of compromise should also check whether mail flow through the gateway was altered or copied during the exposure window.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story






