Root RCE zero-day in Cisco Secure Email Gateway exploited in the wild
Cisco confirms active exploitation of a SQL-injection zero-day in Secure Email Gateway that grants root command execution via crafted email, as CISA adds the flaw to its KEV catalog with a September 17, 2026 federal remediation deadline.
On Monday, Cisco warned that a zero-day in Secure Email Gateway (CVE-2026-76461, CVSS 9.8) is being exploited in the wild; Cisco PSIRT became aware of exploitation in September 2026 and CISA added the flaw to its KEV catalog on Monday, ordering federal agencies to remediate by September 17, 2026. The 9.8 CVSS rating places the bug in the highest severity band, and the active-exploitation status means the score reflects real-world risk rather than theoretical reach.
The vulnerability itself is a SQL-injection flaw (CWE-89) in Cisco AsyncOS Software for Cisco Secure Email Gateway that lets an unauthenticated remote attacker execute arbitrary commands with root privileges by sending a crafted email with malicious SQL. Cisco’s advisory notes the defect affects both physical and virtual gateways regardless of configuration, that no workarounds exist, and that the company has confirmed active exploitation while directly notifying affected Secure Email Cloud customers.
Because the attacker needs no credentials and the executed commands run as root, a single inbound message is sufficient to seize control of the gateway. Email security appliances sit at a network’s trust boundary, so a compromise at this level exposes not just the device but the traffic and policy decisions it mediates.
The CISA action compounds the urgency. By placing CVE-2026-76461 in the Known Exploited Vulnerabilities catalog, the agency has formalized a September 17, 2026 remediation deadline for federal agencies — a timetable that reflects the conviction that exploitation is already ongoing rather than prospective.
What remains striking is the breadth of exposure with no intermediate mitigation. With physical and virtual deployments alike vulnerable irrespective of how they are configured, and with no workaround to blunt the issue, the only meaningful defense is whatever corrective action Cisco has pushed to the customers it notified directly. For the rest of the installed base, the advisory’s confirmation of in-the-wild use means the clock started before the warning did.