Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Cisco Secure Email Gateway zero-day exploited, letting a crafted email run code as root

A flaw in how Cisco's email gateway parses messages lets unauthenticated attackers reach root; Cisco says there is no workaround and compromised virtual units should be rebuilt.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Cisco disclosed on September 14 that CVE-2026-76461, rated 9.8, is under active exploitation in Secure Email Gateway.
  • 2A specially crafted email can trigger SQL injection that may lead to root-level command execution; no workaround exists.
  • 3CISA added the flaw to its exploited-vulnerabilities catalog the same day and gave federal agencies until September 17.

The news

Cisco Systems (CSCO) warned on September 14 of a Cisco Secure Email Gateway zero-day, CVE-2026-76461, that attackers are already exploiting. The flaw lets an unauthenticated attacker send a crafted email that can lead to commands running as root on the appliance.

In its advisory, Cisco said its Product Security Incident Response Team (PSIRT) became aware of active exploitation in September 2026. The company rated the flaw 9.8 out of 10 on the Common Vulnerability Scoring System and said it affects both physical and virtual Secure Email Gateway appliances regardless of configuration. There is no workaround.

According to Cisco, the flaw sits in the email parsing of its AsyncOS software and allows a remote attacker to execute arbitrary SQL statements through a malicious email message, which can lead to root-level command execution on the underlying operating system. Cisco lists Secure Email and Web Manager and Secure Web Appliance as not affected.

Cisco published fixed releases for three software trains: 15.5.5-014 for release 15.5 and earlier, 16.0.4-302 for release 16.0 and 16.5.0-780 for release 16.5. For virtual appliances where exploitation is suspected, the advisory recommends deploying a new instance on fixed software, rebuilding the configuration, and renewing credentials and cryptographic material rather than simply upgrading in place. Owners of suspect physical appliances should contact Cisco's Technical Assistance Center (TAC) and leave remote access enabled for the investigation. Cisco also tells administrators to search the gateway's mail_logs for suspicious SQL statements and to check network and firewall logs outside the device for unexpected transfers.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on September 14 with a remediation deadline of September 17 for federal civilian agencies. Cisco has not said who is behind the attacks or how many customers were hit. Cisco warns that attackers with root may erase or conceal evidence of the intrusion. SecurityWeek noted that this is the second Secure Email Gateway flaw on CISA's list, after CVE-2025-20393, which China-linked actors exploited in late 2025.

The numbers

CVSS severity score
9.8 / 10
Advisory published
Sept 14, 2026
CISA federal patch deadline
Sept 17, 2026
Workarounds available
None

Why CEOs should care

For CISOs, the email gateway sits exactly where attackers want to be: it accepts messages from anyone on the internet and it sees every inbound email. A flaw that is triggered by a message, not a login, means exposure is universal for affected versions. Confirm which release each gateway runs, patch to Cisco's fixed builds, run the mail_logs check and treat any unit that cannot be ruled clean as compromised: rebuild virtual ones, call Cisco TAC for physical ones. Rotating credentials and certificates is the step easiest to skip under time pressure.

For CFOs and IT leaders, recovery is not free. Budget for emergency change windows, clean replacement images for any compromised virtual units, time with Cisco support for physical ones, and the staff time to reissue certificates and keys that the gateway held. Ask whether your managed security provider's contract covers incident rebuilds of appliances it operates, and how quickly it can prove a device is clean.

For boards, the question is structural: how many security appliances does the company run that accept unauthenticated internet traffic, and who tracks exploited flaws in them? CISA gave agencies three days on this one. Ask management whether your own patch policy can meet a three-day window for internet-facing security gear.

The bigger picture

The Cisco bug is part of a broader September run against the security and networking products companies rely on for protection. CISA's catalog also added a Cisco Firewall Management Center authentication bypass on September 9 and a Cisco Identity Services Engine flaw on September 16, alongside exploited bugs in Citrix NetScaler, Fortinet and MikroTik gear. In our view, that is no accident: these devices sit at the network edge, open to the internet, and as this case shows, one flaw can hand an attacker root.

Vendors face new obligations too. Since September 11, the European Union's Cyber Resilience Act has required manufacturers of products with digital elements to send an early warning within 24 hours of becoming aware of an actively exploited vulnerability, with a fuller notification due within 72 hours, according to the European Commission.

What’s next

The advisory already lists indicators of compromise, but not who is behind the attacks. Watch for Cisco updates with attribution, and for incident response firms to publish findings on who exploited the flaw before disclosure. Organizations that find evidence of compromise should also check whether mail flow through the gateway was altered or copied during the exposure window.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

CiscoZero-dayEmail securityCISA

Earlier coverage of Cisco

All Cisco coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.