The Hacker News
Top story
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461 , carries a CVSS score of 9. 8 out of a maximum of 10. 0.
It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system.
"An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," Cisco said in a Monday advisory.
"A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system." The shortcoming affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration.
However, the networking equipment maker said other products like Secure Email and Web Manager and Secure Web Appliance are not impacted.
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release - There are no workarounds other than updating to the latest supported version.
Cisco said it became aware of active exploitation of this vulnerability this month, sharing the following indicators of compromise (IoCs) - Cisco also said it has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected. It did not disclose the scale of the attacks.
"Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges," the company warned. "Because of this level of access, evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors." The development has prompted the U. S.
Cybersecurity and Infrastructure Security Agency (CISA) to add CVE-2026-76461 to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.
The disclosure comes days after Arctic Wolf said it detected large-scale credential attacks targeting internet-facing Fortinet VPN appliances in late August 2026. The high-volume activity took place over two sustained waves across multiple U. S.
customer environments from August 26 through August 28, 2026, generating tens of millions of authentication failures.
"The actor used organization-specific usernames, corporate email addresses, affiliate accounts, and common administrative identities, indicating access to previously collected or enumerated identity information," security researcher Kyle Siddall said .
"The attempted usernames included employee names, corporate email addresses, affiliate identities, and common administrative accounts associated with the targeted organizations.
This targeted identity selection, rather than generic username spraying, indicates access to previously collected or enumerated identity information." In one observed case, a successful Fortinet VPN authentication originating from the IP address "158. 94. 211[.]
14" was followed by malicious activity in the affected environment. See how to test new CVEs against your environment, confirm what attackers can actually exploit, and fix the exposures that pose the greatest risk.
Learn how to identify exploitable risk faster, prioritize what matters most, and reduce exposure before AI-powered attacks accelerate the threat.