Cisco confirmed active exploitation of a root email flaw. Federal agencies got three days.
BleepingComputer reported active exploitation of CVE-2026-76461, affecting Cisco Secure Email Gateway, on 15 September.
Cisco's advisory traces the flaw to "insufficient validation in the email parsing logic". An attacker sends "a crafted email message that contains malicious SQL statements through an affected device".
Cisco says a successful exploit could allow an attacker to "execute arbitrary SQL statements, leading to command execution with root privileges". Cisco says that "in September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability".
CISA added the flaw to its Known Exploited Vulnerabilities catalog on Monday and gave federal agencies until 17 September to patch. That is a three-day window.
Shadowserver tracks more than 400 Secure Email Gateway appliances exposed online.
Cisco tells administrators to check mail_logs for suspicious SQL statements. It also advises cross-referencing network and firewall logs, because root access means the appliance's own logs can be edited.
When your mail gateway gets breached, which log do you trust?
Sources
Every story here is open to read. The ERP LEADERS brief goes one step further.
One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.
Welcome back. · Issue 01
