Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) – Help Net Security

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) – Help Net Security

By Zeljka Zorz
Publication Date: 2026-09-15 11:09:00

Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday.

The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared indicators of compromise that organizations can look for to check whether they’ve been hit.

About CVE-2026-76461

The vulnerability affects versions 16.5, 16.0, and 15.5 and earlier of Cisco AsyncOS Software, running on on-premises physical and virtual Secure Email Gateway appliances.

It also affected the cloud-delivered version of Cisco’s Secure Email Gateway – Cisco Secure Email Cloud – and Cisco said it “has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected.”

The flaw is due to insufficient validation in the email parsing logic, and can be triggered by an unauthenticated attacker sending a…