Cisco Patches Zero-Day in Secure Email Gateway Exploited in Attacks

www.news4hackers.com-cisco-patches-zero-day-in-secure-email-gateway-exploited-in-attacks-cisco-patches-zero-day-in-secure-email-gateway-exploited-in-attacks

Cisco issued an urgent patch for a critical zero-day vulnerability in its Secure Gateway product, which has been actively exploited by threat actors.

Cisco Issues Urgent Patch for Critical Zero-Day Vulnerability

Cisco issued an urgent patch for a critical zero-day vulnerability in its Secure Gateway product, which has been actively exploited by threat actors. The company’s Product Security Incident Response Team (PSIRT) identified the flaw in September 2026 during ongoing monitoring of security threats.

Vulnerability Details and Impact

The vulnerability (CVE-2026-76461) resides in the parsing functionality of Cisco AsyncOS Software used in Secure Gateway appliances, impacting both virtual and physical deployments regardless of configuration settings. Exploitation enables unauthenticated remote attackers to execute arbitrary commands with root-level access on the underlying operating system.

Exploitation Method and Risks

The flaw arises from inadequate validation in the message parsing process, allowing adversaries to inject malicious SQL statements through affected devices. Successful exploitation could result in arbitrary SQL execution, granting attackers full control over the system.

Cisco provided specific indicators of compromise for network defenders to monitor, including anomalous SQL patterns in mail_logs across cluster devices. Administrators are also advised to review network and firewall logs for signs of unauthorized activity such as unusual data transfers.

Shadowserver and CISA Actions

Shadowserver, an internet security watchdog, has identified over 400 internet-exposed Secure Gateway appliances, though the organization has not disclosed how many are honeypots or have already been secured against attacks. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog on Monday, mandating federal agencies to apply patches by September 17.

Additional Vulnerabilities Addressed

In parallel, Cisco addressed four additional critical vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443) affecting Secure Gateway and Secure Email Web Manager appliances. The company noted no evidence of these flaws being exploited in real-world attacks.

Historical Context and Threat Landscape

This follows earlier remediation of a high-severity AsyncOS vulnerability (CVE-2025-20393) in January 2026, which was targeted in zero-day attacks against Secure Gateway and Secure Email Web Manager devices since November 2025. Recent disclosures also reveal three distinct ransomware and state-sponsored threat groups leveraging vulnerabilities in Cisco products.

CISA’s Broader Concerns

CISA has documented 98 Cisco vulnerabilities as actively exploited since November 2021, with seven of these being utilized by ransomware operators. The advisory underscores the ongoing challenges of securing enterprise networking infrastructure against sophisticated cyber threats.



About Author

en_USEnglish