Arbitrary Command Execution Vulnerability in Cisco Secure Email Gateway
CVE-2026-76461

9.8CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
14 September 2026

Badges

🥇 Trended No. 1📈 Trended📈 Score: 29,200💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 28%🦅 CISA Reported📰 News Worthy

What is CVE-2026-76461?

CVE-2026-76461 is a critical vulnerability found in Cisco Secure Email Gateway, which operates on Cisco's AsyncOS software. This email security solution plays a pivotal role in protecting organizations from various email-based threats, including phishing and malware. The identified vulnerability arises from insufficient validation within the email parsing mechanism. As a result, an unauthenticated remote attacker can exploit this flaw by sending a specially crafted email containing malicious SQL statements. If successfully executed, this could lead to arbitrary command execution with root privileges on the system’s underlying operating system, severely compromising an organization’s security posture. The potential for such command execution poses a considerable risk, as it allows attackers to manipulate system operations, access sensitive data, and deploy further malicious activity without authorization.

Potential impact of CVE-2026-76461

  1. Unauthorized System Access: Exploitation of this vulnerability could grant attackers root-level access to the underlying operating system of the Cisco Secure Email Gateway. This level of access could enable them to manipulate system configurations, install malicious software, or carry out other harmful actions unchecked.

  2. Data Breach and Leakage: With control over the email gateway system, attackers could potentially access sensitive organizational data transmitted through email. This exposure may lead to significant data breaches, risking confidential information and violating compliance regulations.

  3. Widespread Malware Distribution: The ability to execute arbitrary commands may allow cybercriminals to disseminate further malware or ransomware throughout the network, potentially affecting additional systems and leading to larger-scale disruptions or data loss across the organization.

CISA has reported CVE-2026-76461

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-76461 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Cisco Secure Email 14.0.0-698

Cisco Secure Email 13.5.1-277

Cisco Secure Email 13.0.0-392

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far

3 weeks ago

Attackers use SQL injection emails to root Cisco gateways

Key points Cisco warns attackers are exploiting a previously unknown flaw, CVE-2026-76461, rated 9.8 out of 10.0, to run arbitrary commands as root on Secure Email Gateway appliances. No login is required,...

3 weeks ago

Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution | eSecurity Planet

Cisco Secure Email Gateway flaw CVE-2026-76461 is actively exploited. See affected AsyncOS versions, fixed releases, and compromise checks now.

4 weeks ago

References

EPSS Score

28% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🥇

    Vulnerability reached the number 1 worldwide trending spot

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 💰

    Used in Ransomware

  • 📰

    First article discovered by Securityweek

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.