Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

https://www.securityweek.com/wp-content/uploads/2024/07/Cisco-switches-network.jpeg

Cisco warned customers on Monday that a zero-day vulnerability affecting Secure Email Gateway appliances has been exploited in the wild.

The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco describes it as an email parsing issue in AsyncOS software that can be exploited remotely and without authentication to execute arbitrary commands on the underlying operating system with root privileges.

The tech giant explained that the critical flaw can be exploited to execute malicious SQL statements by sending them to the targeted user inside a specially crafted email.

Cisco said its PSIRT became aware of the exploitation of CVE-2026-76461 in September 2026, but it has not shared details on attacks involving the zero-day. It’s also unclear who is behind the attacks.

The company has released indicators of compromise (IoCs), but noted that because threat actors can obtain root privileges on a device, they can remove or...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more