vuln-advisorytrade-pressNewsThe Broadside1 min read

Cisco Secure Email Gateway zero-day gets root RCE, KEV-listed

Second AsyncOS email gateway zero-day to hit the KEV catalog in under ten months, both giving unauthenticated attackers root, both exploited before patches shipped.


TL;DR

CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog September 14, a day before Cisco publicly disclosed and patched the actively exploited zero-day in Cisco Secure Email Gateway. The SQL injection flaw in AsyncOS allows unauthenticated, remote attackers to execute commands with root privileges, effectively seizing control of the gateway. Cisco confirmed exploitation before disclosure and has contacted cloud customers where indicators of compromise were found. FCEB agencies face a September 17 due date under BOD 26-04.

The KEV addition carries a three-day clock for federal civilian agencies under BOD 26-04: apply mitigations or, for cloud instances, follow CISA's forensics triage requirements by September 17. That's tight, and it reflects the severity of what Rapid7's Douglas McKee called an "ugly" combination, no authentication required, reachable by sending email through the appliance, and root-level command execution on successful exploitation.

Cisco said its PSIRT became aware of active exploitation in September and has conducted a threat intelligence investigation on Cisco Secure Email Cloud devices. The company is directly contacting customers where indicators of possible compromise surfaced and says it has deployed mitigations within its own management scope. On-premises deployments face a steeper problem: as VulnCheck's Spencer McIntyre noted, root access on a gateway inside the network perimeter opens a pivot point into internal resources. Cloud-hosted gateways are less likely to provide that lateral path, but the passive surveillance risk (silently reading or rerouting email) cuts across both deployment models.

This isn't the first time. CVE-2025-20393, another AsyncOS email gateway vulnerability, was added to KEV in December 2025 after Chinese APT group UAT-9686 exploited it starting in late November, also before a patch was available. That one carried a CVSS 10 and similarly handed unrestricted command execution to unauthenticated attackers. The pattern is hard to miss: the same product line, the same pre-disclosure exploitation window, the same impact class. For agencies and contractors running Cisco Secure Email Gateway, the cadence is becoming its own signal.


Published ·Deep Fathom