Critical Cisco Secure Email Gateway zero-day gives attackers root access
Summary
Cisco has released emergency patches for a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway appliance. The flaw allows attackers to gain root access by sending specially crafted malicious emails, and it has already been exploited in the wild as a zero-day. Cisco advises organizations to upgrade their firmware and monitor logs for signs of compromise, though attackers may attempt to hide their tracks.
IFF Assessment
This vulnerability allows attackers to gain root access to a critical security appliance, posing a significant threat to organizations.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: December 24, 2025. Known ransomware use: Unknown.
Defender Context
This critical vulnerability in Cisco's Secure Email Gateway allows for complete device takeover via email, making it a prime target for attackers. Defenders must prioritize patching and diligently hunt for signs of compromise, as attackers may attempt to cover their tracks by manipulating logs.