Critical Cisco Email Gateway Vulnerability Exposed: Urgent Patches Issued to Combat Exploitation
September 15, 2026
Cisco has updated software to remediate the issue; temporary workarounds are ineffective; Secure Email and Web Manager and Secure Web Appliance are not affected.
The vulnerability affects both physical and virtual Secure Email Gateways regardless of configuration; other Cisco products like Secure Email and Web Manager and Secure Web Appliance are not affected.
As broader warning context, large-scale credential attacks against Fortinet VPNs around the same period illustrate widespread authentication targeting during this wave.
We’re facing a critical, actively exploited vulnerability in Cisco AsyncOS for Secure Email Gateway and Cloud—CVE-2026-76461 with a near-perfect CVSS score of 9.8, allowing unauthenticated remote command execution via crafted emails containing malicious SQL statements.
U.S. CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on September 14, 2026, mandating federal agencies remediate by September 17, 2026.
Cisco has issued patches for the actively exploited zero-day, with exploitation observed since September 2025 across Secure Email Gateway appliances and Secure Email Cloud.
Post-upgrade actions include scanning logs for indicators of compromise, contacting Cisco TAC for physical devices, redeploying a fixed VM for virtual deployments, rebuilding configurations, rotating credentials, and monitoring for anomalies.
Affected versions include AsyncOS 16.5, 16.0, 15.5 and earlier, with remediation guidance extending to Cisco Cloud deployments as well.
The flaw affects both physical and virtual AsyncOS installations regardless of configuration, and there is no workaround beyond applying patches.
Cisco urges organizations to search for indicators of compromise to determine breach impact and to upgrade affected software immediately.
There are no workarounds; monitoring and log analysis are essential to confirm exploitation and track attacker activity.
Affected products include Cisco Secure Email Gateway hardware and virtual deployments, with no workaround currently available.
Summary based on 7 sources
Get a daily email with more Tech stories
Sources

The Hacker News • Sep 15, 2026
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Security Affairs • Sep 15, 2026
U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
Security Affairs • Sep 15, 2026
Cisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day
theregister • Sep 15, 2026
Cisco email security boxes can be rooted by... an email