Jessica Entwistle
September 16 2026
Cisco has confirmed that a zero-day vulnerability in its Secure Email Gateway product has been actively exploited in the wild before a patch was made available. CyberScoop reports that the flaw allows attackers to bypass security controls and gain unauthorised access to email gateway systems, though Cisco has not disclosed the specific nature of the attacks, the scope of impact across its customer base, or the identity of the threat actors involved. A patch has now been released, and Cisco is urging customers to apply it immediately. The company has also published indicators of compromise and guidance to help organisations determine whether their systems have been affected.
For UK organisations using Cisco Secure Email Gateway, this is a high-priority issue that requires immediate attention. Email gateways sit at a critical point in the security architecture, handling inbound and outbound email traffic, filtering malicious content and enforcing data loss prevention policies. A compromised email gateway can provide attackers with access to sensitive communications, the ability to intercept or modify messages, and a foothold for further network compromise. The fact that this vulnerability was exploited before disclosure means that some organisations may already have been affected without knowing it. The operational priority is to patch quickly, review logs for signs of compromise, and ensure that email gateway security is part of regular monitoring and incident response processes. Organisations that rely on third-party managed service providers to operate their email gateways should confirm that their provider is aware of the issue and has taken action.
Organisations should immediately review whether Cisco Secure Email Gateway is deployed in their environment and ensure the patch is applied as a matter of urgency. If the email gateway is managed by a third party or service provider, confirm that they are aware of the issue and have taken action. Review logs for unusual activity or indicators of compromise, including unexpected configuration changes, unauthorised access attempts, or anomalous email traffic patterns. Consider whether email gateway security is included in regular vulnerability scanning, patch management processes and incident response playbooks. Review whether email gateway logs are being collected, retained and monitored as part of security operations. For organisations that have not yet deployed the patch, consider whether temporary mitigations such as network segmentation, access restrictions or enhanced monitoring can reduce risk until patching is complete. Ensure that email security is treated as a foundational control, with clear ownership, regular reviews and integration into broader security monitoring and response processes.
Source: CyberScoop