Criminals are exploiting a Cisco Secure Email Gateway flaw that can turn a malicious email into root access.
Cisco says there are no workarounds, so patching is the only fix.
Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised.
Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise.
CVE-2026-76461 comes less than a year after attackers exploited another AsyncOS flaw, CVE-2025-20393, to break into Cisco Secure Email Gateway appliances and install persistence mechanisms.
5 sentences from our version of the report,
chosen to cover it. Nothing here is written; every line is in the article below.
How
Summarized version
Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks.
The report’s most important sentence, shortened and in plain words. How
Headline check
Headline as published: Cisco email security boxes can be rooted by... an email
There is nothing in this headline a machine can check against the report: no figure, no name and no quotation.
Attackers already exploiting the flaw, and Cisco warns they may be able to cover their tracks once they're in.
Criminals are exploiting a Cisco Secure Email Gateway flaw that can turn a malicious email into root access.
The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix.
The bug lies in how Cisco's AsyncOS software handles incoming email.
Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Help Center support case.
Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise.
The Shadowserver Foundation was tracking more than 400 Cisco Secure Email Gateway appliances exposed to the internet as of Monday.
CVE-2026-76461 comes less than a year after attackers exploited another AsyncOS flaw, CVE-2025-20393, to break into Cisco Secure Email Gateway appliances and install persistence mechanisms.
Shortened to 1 minute
of reading, this version reads 7.1 on the Niral Score.
You are reading our version, not theirs.
This is The Register's report shortened to its most important sentences, in plainer words, with
verdicts and loaded words taken out. Plain description stays, and so do adjectives
that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations
are theirs — quotations are never edited — and the indicators beside it measure
this version. Hover or tap Adjectives to see every one left in the text.
How this outlet filed it, and how we rewrote it
No other newsroom we read has filed on this event, so there is nothing to compare it with yet.
Readers can ask a question about this story here.
Questions and answers are for subscribers.
Sign in
to read them.
Comments are read before they appear where anything in them needs a person to look.
Nothing posted here is ever deleted; a comment taken down keeps its text and the reason,
so the decision can be looked at again. How this works