Cisco Patches Critical Email Gateway Zero-Day Under Active Attack
Cisco has disclosed a critical, actively exploited zero-day vulnerability in its Secure Email Gateway software, urging customers to apply an immediate patch. The flaw, tracked as CVE-2026-76461 and carrying a CVSS score of 9.8, allows an unauthenticated remote attacker to execute arbitrary commands with root privileges by sending a specially crafted email. The vulnerability affects versions 16.5, 16.0, and 15.5 and earlier of Cisco AsyncOS Software for Secure Email Gateway, both physical and virtual appliances. Cisco confirmed the flaw is due to insufficient validation in the email parsing logic and that it is already being exploited in the wild. The company's Product Security Incident Response Team became aware of the active exploitation in September 2025. A successful exploit could grant an attacker complete control over the underlying operating system. Cisco warned that because threat actors may obtain root-level access, they could use it to delete or hide evidence of the compromise. The company cited a prior incident where a suspected Chinese-nexus group used log-purging tools after exploiting a different zero-day. There are no workarounds for the vulnerability.