Our takeCisco confirms active exploitation of CVE-2026-76461 in Secure Email Gateway; attackers can run commands as root. Patch now if you run it yourself.Cyber Resilience desk
Sources (5)
- sophos_xops · sophos_xops
- the420_in · the420_in
- cisa_kev · cisa_kev
- securityweek · securityweek
- hackernews · hackernews
What this means for you — Security leader:If you run Cisco Secure Email Gateway on-prem, apply the AsyncOS patch for CVE-2026-76461 immediately; attackers are actively exploiting it to gain root access.
What this means for you — Lean IT orgs:If you use Cisco Secure Email Gateway, check with your IT provider or MSP today to confirm the patch is applied; most teams without dedicated security staff should treat this as urgent.
What this means for you — MSP:Audit all client Cisco Secure Email Gateway appliances for the CVE-2026-76461 patch; push the AsyncOS update now where it is not yet applied as exploitation is confirmed in the wild.
What this means for you — Researcher:Sophos X-Ops and Cisco confirm active exploitation of CVE-2026-76461 (root command execution) in Cisco Secure Email Gateway; review the advisory for indicators and forensic artifacts.