← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 15, 2026 · 19:56via CSO Online

Critical Cisco Secure Email Gateway zero-day gives attackers root access

Brief

Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released.

Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this appliance’s main job, which means the attack vector is trivial.

“An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in its advisory .

Read more on CSO Online