VYPR
patchPublished Sep 20, 2026· 1 source

Cisco Patches Actively Exploited Email Gateway Zero-Day

Cisco has released security updates to address a critical zero-day vulnerability in its Secure Email Gateway appliances that was being actively exploited in the wild.

Cisco has confirmed the patching of a critical zero-day vulnerability affecting its Secure Email Gateway (SEG) appliances. The vulnerability, identified as CVE-2026-76461, is a SQL injection flaw that attackers have been actively exploiting since at least September 2025.

The exploitation of this flaw allows adversaries to compromise the affected appliances, potentially leading to unauthorized access and data exfiltration. Cisco's Product Security Incident Response Team (PSIRT) became aware of the active exploitation and has since released indicators of compromise (IoCs) to help organizations detect if their systems have been affected. The vendor urges customers to apply the available patches as soon as possible to mitigate the risk.

This incident underscores the persistent threat posed by zero-day vulnerabilities, which by definition lack prior public knowledge and available defenses. The fact that this vulnerability was exploited for over a year before being publicly disclosed and patched highlights the challenges in detecting and responding to such advanced threats. Security teams are advised to monitor their network traffic for the IoCs provided by Cisco and to ensure their SEG appliances are updated to the latest secure versions.

In addition to the Secure Email Gateway vulnerability, Cisco also recently addressed another critical flaw, CVE-2026-76460, an authentication bypass in its Identity Services Engine (ISE) that was also under active exploitation. This dual focus on critical, exploited vulnerabilities in core security products emphasizes the ongoing pressure on network infrastructure and the need for vigilant security practices.

The SQL injection vulnerability (CVE-2026-76461) allows an unauthenticated, remote attacker to inject malicious SQL commands into a vulnerable application. This can lead to the manipulation or disclosure of sensitive data stored within the database. The specific impact can vary depending on the configuration and data stored on the affected SEG appliance.

Cisco's advisory provides detailed information on the affected product versions and the steps required for remediation. Organizations relying on Cisco's email security solutions should prioritize the deployment of these patches to protect their infrastructure from further compromise. The company has not disclosed the exact nature of the data compromised or the specific threat actors involved in the exploitation, but the active exploitation indicates a significant risk.

This event serves as a stark reminder for organizations to maintain robust vulnerability management programs, including timely patching and continuous monitoring for suspicious activity. Proactive threat hunting and the implementation of layered security defenses are crucial in defending against sophisticated attacks that leverage unknown vulnerabilities.

Synthesized by Vypr AI