Cisco is urging customers to immediately patch a critical vulnerability in Cisco Secure Email Gateway, which has already been exploited in the wild.
The zero-day flaw can allow an unauthenticated hacker to execute arbitrary commands using root privileges on an underlying operating system.
The vulnerability, tracked as CVE-2026-76461, is related to the email parsing of Cisco AsyncOS software in Secure Email Gateway. An attacker can exploit the flaw by sending a specially crafted email with malicious SQL statements to an affected device, according to Cisco.
Security researchers warned that the vulnerability can potentially be used by state-linked attacks for espionage.
“The email gateway’s intended purpose is to filter these emails, so it would be easy for an attacker’s message to make it into the device,” Spencer McIntyre, director of exploit development at VulnCheck, told Cybersecurity Dive. “Once exploited, the attacker could pivot into the organization’s network, which is a common outcome from most initial access vulnerabilities.”
Security tooling
Secure Email Gateway was previously known as the IronPort Email Security Appliance and was used to check inbound and outbound email for phishing, business email compromise and other threats, according to a blog post from Rapid7.
The Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies have until Thursday to mitigate the flaw in their respective systems.
Cisco warned the vulnerability affects both physical and virtual versions of Secure Email Gateway, regardless of their configuration. McIntyre said that on-premises versions of Secure Email Gateway would face additional risks, because an attacker would potentially be able to pivot internally.
In the case of organizations using a cloud instance, an attacker would be less likely to gain access to significant internal resources of the targeted organization.
Cisco recommends customers using virtual devices maintain forensics information before deploying a new virtual machine running a fixed version of the software.