Critical Cisco Secure Email Gateway Vulnerability CVE-2026-76461 Exploited for Root Command Execution
A critical vulnerability in Cisco Secure Email Gateway (CVE-2026-76461) is actively exploited in the wild, enabling remote attackers to execute arbitrary commands with root privileges through crafted email messages. The U.S. CISA has added the flaw to its KEV catalog, mandating federal agencies to apply patches by September 17, 2026.
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker
*** END OF TRANSMISSION ***