HackMyIP
← Back to News
2026-09-15 SecurityWeek

Cisco Secure Email Gateway Zero-Day CVE-2026-76461 Exploited for Root RCE

Zero-DayVulnerabilityAPT

Cisco has issued an urgent warning about a critical zero-day vulnerability, tracked as CVE-2026-76461, affecting its Secure Email Gateway (SEG) appliances. The flaw carries a CVSS score of 9.8 and stems from an email parsing issue in AsyncOS software. Attackers can exploit it remotely without authentication by sending a specially crafted email containing malicious SQL statements, achieving arbitrary command execution on the underlying operating system with root privileges. Both physical and virtual SEG deployments are impacted in any configuration, though Secure Email and Web Manager and Secure Web Appliance remain unaffected.

Cisco's PSIRT confirmed awareness of in-the-wild exploitation dating back to September 2026, though the company has not disclosed attacker identities or campaign details. The tech giant published indicators of compromise (IoCs) but cautioned that root-level access allows threat actors to erase forensic traces and evade detection. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog the same day, mandating federal agencies remediate by September 17. This marks only the second Cisco SEG flaw to land on the KEV list, following CVE-2025-20393, which China-linked threat actors began weaponizing in late 2025.

The disclosure lands alongside Cisco and CISA warnings about CVE-2026-20079, a Secure Firewall Management Center vulnerability exploited by Russian state-sponsored actors and financially motivated cybercrime groups, alongside the related FMC weakness CVE-2026-20316. Security teams should prioritize patching SEG appliances immediately, audit logs for anomalous email processing activity, and verify outbound traffic destinations using a reliable DNS leak test to detect covert command-and-control channels. Organizations can also run a port scanner against SEG management interfaces to confirm exposure and check SSL/TLS configurations on perimeter appliances handling inbound mail. Given the severity and root-level access involved, incident response teams should treat any unpatched SEG instance as actively compromised until forensic verification is complete.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →