INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Cisco Zero-Day Exploited in Email Gateways
| 2026-09-17 21:03 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The latest zero-day vulnerability, CVE-2026-76460, has been exploited before Cisco disclosed and patched the vulnerability on Wednesday. Researchers haven't attributed attacks involving this exploit to any known group or threat actor yet, but Landon Rice noted that Cisco ISE vulnerabilities are a recurring target. Multiple vulnerabilities affecting the Cisco product have also been exploited since June 2025, including CVE-2025-20337 and CVE-2025-20281. The vulnerability in question allows remote attackers to bypass authentication and gain full control of affected devices through an API exploit in Cisco Identity Services Engine (ISE). This has been added to the U.S. Cybersecurity and Infrastructure Security Agency's known exploited vulnerabilities catalog, following a similar disclosure last month for CVE-2026-76461.
Technical Mitigations AI-generated
* Implement a secure email filtering system to block malicious emails containing SQL statements, and consider using an email security service that can detect and prevent such attacks.
* Regularly update and patch Cisco Secure Email Gateway software to ensure it has the latest security patches and fixes for CVE-2026-76461.
* Use a web application firewall (WAF) or intrusion detection system (IDS) to monitor incoming traffic and block suspicious activity, including attempts to exploit CVE-2026-76460.
* Configure network segmentation and access controls to limit lateral movement in case of an attack, using techniques such as IPsec, VLANs, or DNSSEC to restrict access to sensitive areas.
* Consider implementing a content security policy (CSP) that enforces strict filtering rules for emails containing malicious code or scripts, reducing the risk of exploitation by attackers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
158.94.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-20337CVE-2025-20337
CVE-2026-76441CVE-2026-76441
CVE-2026-76443CVE-2026-76443
CVE-2026-76460CVE-2026-76460
CVE-2026-20353CVE-2026-20353
CVE-2026-76440CVE-2026-76440
CVE-2026-76461CVE-2026-76461
CVE-2025-20281CVE-2025-20281
CVE-2025-20393CVE-2025-20393
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
November 2021
Ransomware gangs exploited a recently discovered Cisco vulnerability in email gateways starting from November 2021.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, CISA has
flagged 98 Cisco vulnerabilities
as actively exploited in attacks, including seven abused by ransomware gangs.
general_metric
98 Cisco vulnerabilities
Since November 2021, CISA has
flagged 98 Cisco vulnerabilities
as actively exploited in attacks, including seven abused by ransomware gangs.
June 2025
Threat actors exploited a zero-day vulnerability in Cisco email gateways starting from June 2025.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-20337
Multiple vulnerabilities affecting the Cisco product have been exploited since June 2025, including
CVE-2025-20337
and
CVE-2025-20281
.
vulnerability
CVE-2025-20281
Multiple vulnerabilities affecting the Cisco product have been exploited since June 2025, including
CVE-2025-20337
and
CVE-2025-20281
.
organisation
CVE-2025
Multiple vulnerabilities affecting the Cisco product have been exploited since June 2025, including
CVE-2025-20337
and
CVE-2025-20281
.
the summer of 2025
Threat actors exploited a zero-day vulnerability in Cisco email gateways.
November 2025
Threat actors exploited a maximum-severity Cisco AsyncOS vulnerability (CVE-2025-20393) in SEG and SEWM email gateways.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-20393
In January, the company also
patched a maximum-severity Cisco AsyncOS flaw
(CVE-2025-20393) exploited in zero-day attacks against SEG and SEWM devices
since November 2025
.
organisation
SEG
In January, the company also
patched a maximum-severity Cisco AsyncOS flaw
(CVE-2025-20393) exploited in zero-day attacks against SEG and SEWM devices
since November 2025
.
late August 2026
Threat actors exploited a previously unknown zero-day vulnerability in Cisco's email gateways.
August 26
Threat actors exploited a previously unknown zero-day vulnerability in Cisco email gateways.
August 28, 2026
Threat actors exploited a previously unknown zero-day vulnerability in Cisco email gateways.
September 14, 2026
Threat actors exploited a zero-day vulnerability in Cisco Secure Email Gateway.
September 14
Threat actors exploited a zero-day vulnerability in Cisco email gateways.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-76461
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
attribution
KEV
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
target_region
United States
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
attribution
Known Exploited Vulnerability
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
general_metric
76461 CVE-2026
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
September 15, 2026
Threat actors used a previously unknown vulnerability in Cisco's Secure Email Gateway to gain root access through malicious emails.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 15, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog.
attribution
Known Exploited
U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 15, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog.
Sep 15, 2026
Threat actors exploited a previously unknown vulnerability in Cisco email gateways.
September 17, 2026
Threat actors exploited a zero-day vulnerability in Cisco email gateways to gain unauthorized access.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-76461
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
CVE-2026-76461 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.
tactic
T1588.006 - Vulnerabilities
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
CVE-2026-76461 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.
attribution
KEV
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
CVE-2026-76461 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.
general_metric
76461 CVE-2026
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
CVE-2026-76461 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.
attribution
Known Exploited
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
CVE-2026-76461 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.
attribution
FCEB
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
CVE-2026-76461 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.
attribution
Federal Civilian Executive Branch
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
CVE-2026-76461 to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 17, 2026.
September 17
Threat actors exploited a zero-day vulnerability in Cisco's email gateways.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-76461
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
Internet-exposed Cisco Secure Email Gateway appliances (Shadowserver)
The Cybersecurity and Infrastructure Security Agency (CISA) also
added
the CVE-2026-76461 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog on Monday
, ordering federal agencies to patch their systems within three days, by September 17.
attribution
KEV
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
Internet-exposed Cisco Secure Email Gateway appliances (Shadowserver)
The Cybersecurity and Infrastructure Security Agency (CISA) also
added
the CVE-2026-76461 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog on Monday
, ordering federal agencies to patch their systems within three days, by September 17.
target_region
United States
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
attribution
Known Exploited Vulnerability
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
general_metric
76461 CVE-2026
On September 14, US CISA
added
CVE-2026-76461 to its Known Exploited Vulnerability to Catalog (KEV) and ordered federal organizations to address it by September 17.
tactic
T1588.006 - Vulnerabilities
Internet-exposed Cisco Secure Email Gateway appliances (Shadowserver)
The Cybersecurity and Infrastructure Security Agency (CISA) also
added
the CVE-2026-76461 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog on Monday
, ordering federal agencies to patch their systems within three days, by September 17.
attribution
Known Exploited
Internet-exposed Cisco Secure Email Gateway appliances (Shadowserver)
The Cybersecurity and Infrastructure Security Agency (CISA) also
added
the CVE-2026-76461 flaw to its
Known Exploited Vulnerabilities (KEV) Catalog on Monday
, ordering federal agencies to patch their systems within three days, by September 17.
2026/09/17
An attacker could exploit the Cisco Secure Email Gateway flaw by sending a crafted email message that contains malicious SQL statements through an affected device.
Click on any entity below to view its context and source!
organisation
CVE-2026-76460
Researchers haven’t attributed attacks involving CVE-2026-76460 to any known group or threat actor, but Rice noted Cisco ISE vulnerabilities are a recurring target.
organisation
CVE-2026-76461
Cisco didn’t say when the first instance of CVE-2026-76460 exploitation occurred, but the disclosure came just two days after the vendor disclosed CVE-2026-76461, an actively exploited
zero-day vulnerability in Cisco Secure Email Gateway
.
Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances.
organisation
CVE-2026
CVE-2026-76460 and CVE-2026-76461 affect different codebases,” the spokesperson added.
organisation
Cisco Secure Email
Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation.
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution.
organisation
Secure Email Gateway
Cisco disclosed a critical zero-day, tracked as CVE-2026-76461 (CVSS score of 9.8), affecting Secure Email Gateway appliances.
organisation
CVSS
The vulnerability, tracked as
CVE-2026-76461
, carries a CVSS score of 9.8 out of a maximum of 10.0.
organisation
API of Cisco Identity Services Engine
The defect in an API of Cisco Identity Services Engine (ISE) allows a remote attacker to bypass authentication and gain full control of the affected device.
organisation
CyberScoop
“ISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs, and move laterally into every network segment ISE controls,” Landon Rice, senior exploit developer at VulnCheck, told CyberScoop.
Spencer McIntyre, director of exploit development at VulnCheck, told CyberScoop the exploit could allow an attacker to maintain access to the email gateway and monitor communications.
organisation
Enables Root Command Execution
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution.
organisation
SQL
SQL injection flaw in the email parsing functionality of Cisco AsyncOS
Attackers can send specially crafted emails containing malicious SQL statements, triggering arbitrary command execution on the underlying system with root privileges.
An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," Cisco added.
"An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," Cisco
said
in a Monday advisory.
organisation
Cisco Secure Email Gateway
Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.”
Software for Cisco Secure Email Gateway in September.
Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration.
Software for Cisco Secure Email Gateway has come under active exploitation in the wild.
Recommended actions
Counter Threat Unit™ (CTU) researchers recommend that organizations identify vulnerable versions of Cisco AsyncOS for Cisco Secure Email Gateway in their environments and upgrade as appropriate.
infrastructure
15.5
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
infrastructure
15.5.5-0141
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
infrastructure
16.0
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
infrastructure
16.0.4-302
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
infrastructure
16.5
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
infrastructure
16.5.0-780
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
organisation
Counter Threat Unit
Recommended actions
Counter Threat Unit™ (CTU) researchers recommend that organizations identify vulnerable versions of Cisco AsyncOS for Cisco Secure Email Gateway in their environments and upgrade as appropriate.
organisation
Cisco
Cisco says customers using Secure Email Cloud may not be able to check these indicators themselves, but those with detected malicious activity were contacted directly.
Cisco said it became aware of active exploitation of this vulnerability this month, sharing the following indicators of compromise (IoCs) -
Review mail_logs and look for suspicious SQL statements.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Secure Email Gateway)
organisation
Cisco Secure Email Cloud
Cisco has directly contacted customers who own Cisco Secure Email Cloud devices where indicators of possible compromise were identified,” the company wrote in its security advisory.
Cisco also said it has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected.
organisation
VulnCheck
Researchers at Rapid7 and VulnCheck said they don’t yet know how many organizations are impacted by active exploits, but they encouraged Cisco customers to patch and hunt for potential signs of compromise as soon as possible.
organisation
CVE-2026-76440
On Monday, Cisco addressed
four other critical vulnerabilities
(CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443) affecting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances regardless of configuration, but said it had no evidence they have also been exploited in the wild.
organisation
CVE-2026-76441
On Monday, Cisco addressed
four other critical vulnerabilities
(CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, and CVE-2026-76443) affecting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances regardless of configuration, but said it had no evidence they have also been exploited in the wild.
organisation
IP
However, admins should also cross-check network and firewall logs for signs of suspicious activity (including uploads and downloads to and from external or malicious IP addresses) because attackers may remove evidence of exploitation.
"
As a result, administrators are recommended to cross-check the network logs and the firewall logs outside of the impacted device to identify any potential anomalous activity, including unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Vulnerability / Network Security
Ravie Lakshmanan
Sep 15, 2026
Vulnerability / Network Security
Cisco has warned that a new critical vulnerability impacting AsyncOS
organisation
Secure Email
However, the networking equipment maker said other products like Secure Email and Web Manager and Secure Web Appliance are not impacted.
organisation
Large-Scale Credential Attacks Target Fortinet
Large-Scale Credential Attacks Target Fortinet VPNs
organisation
Fortinet VPN
"
In one observed case, a successful Fortinet VPN authentication originating from the IP address "158.94.211[.]14" was followed by malicious activity in the affected environment.
September 2026
Threat actors exploited a zero-day vulnerability in Cisco email gateways.
Tactical Metrics
Metrics
infrastructure
15.5
Software Version
Click for context!
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
Metrics
infrastructure
15.5.5-0141
Software Version
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
Metrics
infrastructure
16.0
Software Version
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
Metrics
infrastructure
16.0.4-302
Software Version
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
Metrics
infrastructure
16.5
Software Version
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
Metrics
infrastructure
16.5.0-780
Software Version
Fixes are available for the following versions of Cisco AsyncOS for Cisco Secure Email Gateway Software Release -
15.5 and earlier (Fixed in 15.5.5-0141)
16.0 (Fixed in 16.0.4-302)
16.5 (Fixed in 16.5.0-780)
Intelligence Sources
BleepingComputer
2026-09-15
Cisco patches Secure Email Gateway zero-day exploited in attacks
BleepingComputer
The Hacker News
2026-09-15
CyberScoop
2026-09-15
Security Affairs
2026-09-15
Security Affairs
2026-09-15
Sophos News
2026-09-15
CyberScoop
2026-09-17
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-18T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
CVE-2026-76460
entity
17x
timeline
Temporal Reference
June 2025
date
13x
attribution
Attributing Entity
the U.S. Cybersecurity and Infrastructure Security Agency
authority
9x
vulnerability
Exploited CVE
CVE-2026-76460
cve
6x
infrastructure
Software Version
15.5
version
2x
tactic
MITRE ATT&CK Technique
T1592.002 - Software
technique
2x
tactic
Cyber Operation Type
Espionage
tactic
Contextual Telemetry
Context Block
6 METRICS
vulnerability
CVSS Score
10
score
target region
Target Country
United States
country
general metric
Cve-2026
76,461
cve-2026
general metric
Cisco Vulnerabilities
98
cisco vulnerabilities
general metric
Gateway Appliances
400
gateway appliances
general metric
Sep
15
sep
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.