Cisco confirmed this week that a critical zero-day in its Secure Email Gateway software, tracked as CVE-2026-76461 with a CVSS score of 9.8, has been under active exploitation since early September. The company only released a patch on Monday, weeks after attackers started using it. CISA has already added the flaw to its Known Exploited Vulnerabilities catalogue and given US federal agencies until Thursday, 17 September, to fix it, which is about as loud an alarm bell as this kind of advisory gets.
If your business or your IT provider runs a Cisco Secure Email Gateway, whether as a physical appliance, a virtual one, or the cloud-delivered Secure Email Cloud service, this is worth checking today rather than filing away for later.
What the flaw actually does
The bug sits in how AsyncOS, the software behind Cisco’s email gateways, parses incoming messages. Insufficient validation of certain fields means an attacker can send a single crafted email containing malicious SQL statements and use it to run arbitrary commands with root privileges on the underlying system, no login required. That’s about as bad as a vulnerability gets: full, unauthenticated control of the device that sits between your business and every email you receive.
Security researchers at Shadowserver are already tracking several hundred exposed Cisco Secure Email Gateway appliances online. It isn’t clear yet how many have actually been compromised, but the combination of a working exploit, a widely deployed product, and a multi-week gap between exploitation starting and a patch existing is exactly the pattern that tends to end in real breaches for the organisations that don’t act quickly.
What to check if you run Cisco Secure Email Gateway
Affected versions are 15.5, 16.0 and 16.5, and earlier releases of AsyncOS, across both on-premises appliances and the cloud-hosted version. If you manage this in-house, the priority is simple: apply Cisco’s patch now, and don’t wait for a routine maintenance window. If a managed service provider or IT partner runs your email security for you, ask them directly, today, whether any of your infrastructure is affected and whether the fix has already been applied. Don’t assume it has just because you pay someone to look after it; patches on internet-facing security appliances sometimes sit in a queue behind other work unless someone flags urgency.
If you’re not sure what email gateway your business runs, that’s worth finding out regardless of this specific flaw. A surprising number of UK SMEs inherited their email security setup from a previous IT contract and nobody currently on staff could name the vendor if asked. A monitoring service like KeepSafe exists precisely for this gap: it watches for exposed, unpatched, or misconfigured internet-facing systems so you find out from an alert rather than from a ransom note.
The wider lesson, even if you’re not on Cisco
Email gateways, VPNs and other perimeter security devices have become one of the most reliable ways attackers get into small business networks, precisely because they’re internet-facing by design and patched less consistently than laptops and servers. This is at least the third such advisory covered on this site in the past few months, following similar critical flaws in other vendors’ edge devices. The pattern is consistent enough that it’s worth a five-minute conversation with whoever manages your network: what’s exposed to the internet, who owns patching it, and how quickly does that actually happen in practice.
The takeaway: if you run Cisco Secure Email Gateway in any form, patch it today, don’t wait for confirmation that you’ve been targeted. And if you don’t know whether you run it, that uncertainty is itself the thing to fix first.