Cisco Secure Email Gateway zero-day exploited for root-level access
CVE-2026-76461 is reported as an unauthenticated SQL-injection zero-day exploited against Cisco Secure Email Gateway, potentially enabling root-level command execution; it is reportedly in CISA KEV with a September 17 federal deadline. Patch or rebuild immediately and investigate for prior compromise, log wiping, unauthorized access, persistence, email espionage, and outbound activity; rotate credentials and cryptographic material.
Sources (3)
Updated Sep 16, 2026