Ethical Hacking News
Cisco has issued a warning about a critical zero-day vulnerability in its Secure Email Gateway, which has been exploited in the wild to gain root access through malicious emails. The vulnerability affects both physical and virtual appliances, regardless of device configuration, and has a CVSS score of 9.8. Organizations are urged to take immediate action to address the vulnerability and protect their systems and data from potential exploitation.
Cisco has issued a warning about a critical zero-day vulnerability in its Secure Email Gateway. The vulnerability, CVE-2026-76461, has a CVSS score of 9.8 and affects both physical and virtual devices. The vulnerability is due to insufficient validation in email parsing logic, allowing attackers to execute arbitrary commands with root privileges. There are no workarounds to address the issue, and customers may not be able to detect suspicious activity themselves. Federal organizations are ordered to address the vulnerability by September 17.
Cisco has recently issued a warning regarding a critical zero-day vulnerability in its Secure Email Gateway, which has been exploited in the wild to gain root access through malicious emails. The vulnerability, tracked as CVE-2026-76461, has a CVSS score of 9.8 and affects both physical and virtual Cisco Secure Email Gateway appliances, regardless of device configuration.
The vulnerability is due to insufficient validation in the email parsing logic, allowing an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Attackers can exploit this vulnerability by sending a crafted email message containing malicious SQL statements through an affected device, which can lead to command execution with root privileges on the underlying system.
According to the advisory, there are no workarounds that address this issue, and customers using Secure Email Cloud may not be able to check for suspicious SQL statements themselves. However, those with detected malicious activity were contacted directly. To confirm any attempted exploitation of this vulnerability, customers are advised to review the mail_logs and look for suspicious SQL statements, such as the following example: "cisco-esa>grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]".
This vulnerability has been added to the Known Exploited Vulnerabilities catalog by the US CISA, and federal organizations are ordered to address it by September 17. The advisory also warns that the presence of any entry in the output may indicate malicious activity.
This critical zero-day vulnerability highlights the importance of keeping software up-to-date and being cautious when interacting with emails that seem suspicious. As the threat landscape continues to evolve, it is essential for organizations to stay informed and take proactive measures to protect their systems and data.
Related Information:
https://www.ethicalhackingnews.com/articles/Cisco-Warns-of-Critical-Email-Gateway-Zero-Day-Exploitation-A-Growing-Threat-in-the-Digital-Landscape-ehn.shtml
https://securityaffairs.com/199137/hacking/cisco-warns-of-ongoing-exploitation-of-critical-email-gateway-zero-day.html
https://nvd.nist.gov/vuln/detail/CVE-2026-76461
https://www.cvedetails.com/cve/CVE-2026-76461/
Published: Tue Sep 15 09:17:56 2026 by llama3.2 3B Q4_K_M