MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-15 · via BleepingComputer

Cisco fixes actively exploited email gateway flaw allowing root access

Image via BleepingComputer
Image via BleepingComputer

Cisco has released patches for a critical vulnerability in its Secure Email Gateway products that attackers have been actively exploiting. The flaw, tracked as CVE-2026-76461, stems from insufficient validation in email parsing and lets unauthenticated remote attackers execute arbitrary commands with root privileges. Cisco has shared indicators of compromise, and CISA has added the bug to its known exploited vulnerabilities catalog, requiring federal agencies to patch within three days.

Expanded Detail

Cisco’s advisory notes the flaw exists in both virtual and physical Secure Email Gateway appliances, independent of configuration. Attackers exploit it by sending a crafted email containing malicious SQL statements, which can lead to arbitrary command execution with root privileges. Cisco has published indicators of compromise, urging administrators to inspect mail logs for suspicious SQL activity and to review network and firewall logs for external connections, as attackers may erase evidence. Shadowserver currently tracks over 400 exposed appliances, though it does not specify how many are honeypots or already patched.

The same advisory also details four additional critical vulnerabilities affecting Secure Email Gateway and Secure Email and Web Manager products, though Cisco states there is no evidence these have been exploited in the wild. This incident follows a January patch for a maximum-severity AsyncOS flaw used in zero-day attacks since November 2025. Separately, Cisco recently disclosed that three ransomware and state-sponsored groups exploited two Secure Firewall Management Center flaws. Since November 2021, CISA has cataloged 98 Cisco vulnerabilities as actively exploited, including seven tied to ransomware gangs.

Context

This vulnerability could have broad consequences for organizations relying on Cisco Secure Email Gateway as a frontline defense. Successful exploitation grants root access, potentially allowing attackers to intercept, alter, or delete email traffic, pivot into internal networks, or deploy persistent backdoors. Federal agencies face a tight three-day patch deadline, but private-sector firms may lag, leaving critical infrastructure and enterprises exposed. The active exploitation suggests threat actors are moving quickly, and the inclusion in CISA’s KEV catalog underscores urgency. While Cisco’s patches mitigate the immediate risk, the incident highlights how email parsing flaws remain a favored entry point for sophisticated attackers.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Cisco warns of active exploitation of critical firewall management flaw · Cybersecurity
CISA flags active exploitation of critical GitLab vulnerability · Cybersecurity
Ransomware Gangs Join Attacks on Unpatched WatchGuard Fireboxes · Cybersecurity
Chrome Vulnerability Actively Exploited in the Wild Triggers Emergency Update · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Cisco patches Secure Email Gateway zero-day exploited in attacks.” Browse more stories.