Cisco Secure Email Gateway Zero-Day Vulnerability: Active Exploitation of Root RCE
Cisco has issued an urgent alert regarding a critical remote code execution (RCE) vulnerability affecting Secure Gateway appliances, confirming that it is currently being exploited in real-world scenarios.
Vulnerability Overview
Cisco has issued an urgent alert regarding a critical remote code execution (RCE) vulnerability affecting Secure Gateway appliances, confirming that it is currently being exploited in real-world scenarios. The flaw, tracked as CVE-2026-76461, resides in the AsyncOS software component and allows threat actors to execute arbitrary commands on the underlying operating system with root-level privileges. The vulnerability requires no authentication and can be triggered remotely, making it highly dangerous for affected systems.
CVE-2026-76461 Details
The flaw stems from a parsing error within the AsyncOS framework, which enables attackers to inject malicious SQL statements through specially crafted inputs. Cisco’s Product Security Incident Response Team (PSIRT) first detected exploitation attempts in September 2026, though no specific attack details or threat actor attribution have been disclosed.
Exploitation and Response
The company has released indicators of compromise (IoCs) to aid in detection, but warned that adversaries with root access could manipulate or erase these traces to evade detection. The vulnerability impacts all physical and virtual iterations of Secure Gateway, regardless of configuration. However, Secure Web Manager and Secure Web Appliance products are not affected.
CISA Involvement and KEV Listing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included CVE-2026-76461 in its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to remediate the issue by September 17, 2026. This marks the second Cisco Secure Gateway vulnerability listed in the KEV catalog, following CVE-2025-20393, which was linked to China-associated threat groups in late 2025.
Internal Discovery and Broader Context
Cisco disclosed that CVE-2026-76461 was identified internally as part of broader assessments of its Secure Gateway and Secure Web Manager product lines. The revelation comes shortly after Cisco and CISA warned of ongoing attacks leveraging CVE-2026-20079, a separate vulnerability in the Secure Firewall Management Center (FMC), and another FMC flaw designated CVE-2026-20316.
Mitigation and Recommendations
The flaw’s high CVSS score of 9.8 underscores its severity, with potential consequences including full system compromise, data exfiltration, and persistent backdoor access. Organizations using affected Cisco Secure Gateway systems are advised to apply patches immediately and monitor for signs of exploitation. The lack of transparency around the attack timeline and actor motivations highlights the urgency of proactive mitigation measures.
