• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / Cisco Secure Email Gateway zero-day exploited before patch

Cisco Secure Email Gateway zero-day exploited before patch

byLotfi Ben Taleb
September 15, 2026
in Security
Reading Time: 3 mins read
Close-up of teal fiber optic cables plugged into a Cisco Nexus network switch
Share on Facebook
Share on Twitter

Cisco has confirmed that a secure email gateway flaw, tracked as CVE-2026-76461, is under active exploitation and lets an unauthenticated attacker take root on the underlying operating system. The vulnerability affects AsyncOS Software, the operating system that runs Cisco’s Secure Email Gateway appliances, and Cisco rates it 9.8 out of a maximum 10.0 on the CVSS scale. A patch is now available, but exploitation began before it shipped, which is what makes this a genuine zero-day rather than a routine advisory.

The appliance sits at the edge of an organisation’s mail flow, scanning inbound and outbound messages for spam, malware and policy violations before they reach a mailbox, which is exactly the kind of exposed, internet-facing role that makes an unauthenticated root flaw dangerous.

How the secure email gateway flaw lets an outsider become root

The root cause sits in how the gateway parses incoming mail. Secure Email Gateway appliances inspect every message that passes through them, unpacking headers, attachments and encoded content to decide whether to deliver, quarantine or drop it. Insufficient validation in that parsing logic means a specially crafted email can make the appliance execute commands it was never meant to run. No login is required and no privilege escalation step is needed: the code runs as root on the underlying operating system from the first malicious message the appliance processes.

That combination, no authentication and immediate root, is why the flaw sits at the top of the CVSS scale. A gateway that can be turned against itself by an incoming email is a worse problem than most remote code execution bugs, because the attack surface is exactly the traffic the appliance exists to process. There is no way to simply block the feature that is vulnerable without turning off mail filtering altogether.

What Cisco’s advisory confirms

Cisco’s advisory and the CVE record published on NVD lay out the scope: the affected product is Secure Email Gateway running AsyncOS Software, the attack requires no credentials, and successful exploitation hands the attacker root, the highest privilege level on the appliance. Cisco has shipped a fix. The outstanding problem for defenders is that the flaw was already being used against real targets before that fix existed, which is what separates a zero-day from an ordinary patch cycle.

Patching closes the hole but does not undo anything that happened before the fix was applied. Because the flaw required no credentials, a gateway that was reachable from the internet before the patch shipped could have been used without leaving the kind of login trail that shows up in access logs. Anyone who has not patched yet should treat the appliance as already touched until logs say otherwise, not the other way round.

A compromised gateway is not just a mail-routing problem: it sits between the internet and every inbox behind it, so root access there gives an attacker visibility into message content and credentials moving through the organisation, the same category of fallout as the passport and financial data exposed in Revolut’s own breach disclosure.

What to watch

Anyone running Secure Email Gateway should check the build number against Cisco’s advisory and apply the patch immediately rather than waiting for a scheduled maintenance window: this is not a vulnerability that rewards delay. Watch Cisco’s advisory page for updates to the list of affected AsyncOS releases, since those lists are sometimes revised after initial disclosure as more testing comes in, and watch for incident-response write-ups describing what the in-the-wild attacks actually did once they had root.

Tags: vulnerability
Previous Post

Intel scraps 12-core Xe GPU for Nova Lake-S desktop chips

Next Post

iPhone Duo 3D model lets you open the hinge before launch

Related Posts

Tangled colored network patch cables running into a server rack panel
Security

Citrix confirms two NetScaler zero-days under active attack

September 28, 2026
Rows of blue-lit server hard drive caddies in a data center rack
Security

ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

September 27, 2026
Rendered illustration of a data center corridor lined with server racks showing blue status lights
Security

WSO2 and Adobe Commerce flaws land on CISA’s exploited list

September 26, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

October 1, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply