Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
A critical zero-day vulnerability (CVE-2026-76461) in Cisco Secure Email Gateway is actively being exploited in the wild, allowing attackers to execute arbitrary commands with root privileges. Cisco has released IoCs, but due to the exploit's capabilities, attackers can easily remove them. This is the second Cisco Secure Email Gateway vulnerability this year, following a similar exploit by Chinese threat actors.
Cisco warned customers on Monday that a critical zero-day vulnerability (CVE-2026-76461) affecting Secure Email Gateway appliances has been exploited in the wild. The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco describes it as an email parsing issue in AsyncOS software that can be exploited remotely and without authentication to execute arbitrary commands on the underlying operating system with root privileges.
Cisco’s PSIRT became aware of the exploitation of CVE-2026-76461 in September 2026, but it has not shared details on attacks involving the zero-day. It’s also unclear who is behind the attacks.
The company has released indicators of compromise (IoCs), but noted that because threat actors can obtain root privileges on a device, they can remove or hide IoCs to cover their tracks. The security hole affects both the physical and virtual versions of Secure Email Gateway in any configuration. Secure Email and Web Manager and Secure Web Appliance are not impacted.
CISA added CVE-2026-76461 to its KEV catalog on Monday and instructed federal organizations to address it by September 17. This is only the second Cisco Secure Email Gateway vulnerability in the KEV list, after CVE-2025-20393, which China-linked threat actors started exploiting in late 2025.
CVE-2026-76461 is one of several vulnerabilities Cisco discovered internally in its Secure Email Gateway and Secure Email and Web Manager products. News of CVE-2026-76461’s exploitation comes just days after Cisco and CISA warned organizations about attacks leveraging CVE-2026-20079, a Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. Cisco warned that CVE-2026-20079 and another FMC weakness tracked as CVE-2026-20316 have been exploited by both Russian state-sponsored hackers and profit-driven cybercriminals.