Critical Cisco Secure Email zero-day under active exploitation

 

Critical Cisco Secure Email zero-day under active exploitation

Cisco has released security updates addressing multiple vulnerabilities in its Secure Email products, including a critical zero-day vulnerability that is being actively exploited in the wild.

The security issues affect Cisco Secure Email Gateway (SEG) and Cisco Secure Email and Web Manager (SEWM). The most serious vulnerability, tracked as CVE-2026-76461, carries a maximum CVSS v4 score of 10.0 and can allow a remote, unauthenticated attacker to execute arbitrary commands with root privileges.

CVE-2026-76461 is an SQL injection vulnerability in Cisco Secure Email Gateway. The issue stems from insufficient input validation in the product's email parsing logic.

An unauthenticated remote attacker can exploit the vulnerability by sending a specially crafted email containing malicious SQL statements. Successful exploitation can result in arbitrary command execution with root privileges on the underlying operating system, potentially giving an attacker complete control over the affected appliance.

Cisco has confirmed that the vulnerability is being actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability affects Cisco Secure Email Gateway versions 15.5 through 16.5.0-748. Security updates are available.

Cisco also released a security hardening update addressing five additional vulnerabilities affecting Cisco Secure Email Gateway and Secure Email and Web Manager. The flaws can potentially allow remote attackers to bypass security restrictions, compromise affected systems, or cause denial-of-service conditions.

The vulnerabilities include:

  • CVE-2026-20353 – Improper resource lifetime management vulnerability with a CVSS v4 score of 9.3. A remote attacker can exploit the issue to bypass security restrictions and compromise an affected system.
  • CVE-2026-76440 – Relative path traversal vulnerability rated 9.3 that can allow a remote attacker to compromise the affected system using a specially crafted pathname.
  • CVE-2026-76441 – Improper access control vulnerability rated 9.3. Specially crafted network requests can be used to compromise a vulnerable system.
  • CVE-2026-76442 – Input validation vulnerability with a CVSS v4 score of 8.7 that can be exploited remotely to cause a denial-of-service condition.
  • CVE-2026-76443 – Improper neutralization vulnerability rated 9.3 that can allow crafted input to compromise an affected system.

The additional vulnerabilities affect Cisco Secure Email Gateway versions 15.5 through 16.5.0-748 and Cisco Secure Email and Web Manager versions 15.5 through 16.0-195.

The presence of an actively exploited, remotely accessible vulnerability capable of providing root-level command execution makes CVE-2026-76461 particularly dangerous. Organizations operating affected Cisco Secure Email appliances should prioritize deployment of the available security updates.

Because exploitation of the zero-day can be initiated through a crafted email and does not require authentication or user interaction, vulnerable Internet-facing email security infrastructure should be considered at elevated risk until patched.

Cisco has released fixed software versions 15.5.5-014, 16.0.4-302, and 16.5.0-780 for the affected products, and administrators should upgrade vulnerable installations as soon as possible. Organizations should also investigate affected systems for indications of compromise, particularly where vulnerable Cisco Secure Email Gateway versions were exposed while CVE-2026-76461 was being actively exploited.

More technical information, affected versions and remediation details are available in the Cybersecurity Help security bulletins for CVE-2026-76461 and Cisco Secure Email Gateway and the five additional Cisco Secure Email vulnerabilities.

Back to the list