Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
Reported exploitedSecure Email GatewaySecure Firewall Management CenterOur summary
Cisco has disclosed that a critical zero-day vulnerability, tracked as CVE-2026-76461, is currently being actively exploited against its Secure Email Gateway appliances. With a CVSS score of 9.8, this flaw in the AsyncOS software enables unauthenticated attackers to achieve root-level access and execute arbitrary commands by sending specially crafted emails containing malicious SQL statements. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog, urging federal agencies to remediate the issue urgently. While specific threat actors have not been identified, the exploitation highlights severe risks for both physical and virtual instances of the Secure Email Gateway.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.