Jessica Entwistle
September 15 2026
Cisco has confirmed that a critical vulnerability in AsyncOS Software for Cisco Secure Email Gateway is being actively exploited in the wild. CVE-2026-76461 carries a CVSS score of 9.8 and allows an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system with root privileges. The flaw stems from insufficient validation in the email parsing logic, and exploitation does not require authentication or user interaction. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalogue, and Cisco has released patches for affected versions.
Cisco Secure Email Gateway is widely deployed across UK organisations for email security, spam filtering and threat protection. The fact that this vulnerability is already being exploited in the wild means that any organisation running an unpatched version is at immediate risk of compromise. Root-level command execution gives an attacker complete control over the email gateway, which could be used to intercept communications, deploy further malware, pivot into internal networks, or exfiltrate sensitive data passing through the mail system. Email gateways sit at a critical point in most organisations' infrastructure, making them high-value targets for attackers seeking initial access or persistent visibility into business communications. The lack of authentication requirement means that exploitation can occur remotely without any prior access to the network.
For UK businesses running Cisco Secure Email Gateway, this is a prompt to verify patch status immediately and ensure monitoring is in place to detect any signs of compromise. If patching cannot be completed quickly, consider whether temporary mitigations or increased monitoring can reduce exposure until updates are applied. Review logs for any suspicious activity around the email gateway, including unexpected command execution, configuration changes or unusual network connections. Ensure that responsibility for patching critical infrastructure components like email gateways is clearly assigned and that processes are in place to respond quickly when vendors release emergency patches for actively exploited vulnerabilities. Consider whether your current vulnerability management process would have identified and prioritised this issue quickly enough to prevent exploitation.
Source: SecurityWeek