U.S. Cyber Agency Says a Cisco Email Flaw Is Already Being Exploited

The U.S. Cybersecurity and Infrastructure Security Agency added a flaw in Cisco's Secure Email Gateway to its Known Exploited Vulnerabilities catalog on Sept. 14, 2026, saying it had evidence that attackers are already using it. Cisco published a fix the same day.
That gateway is the appliance many organizations put in front of their corporate mail to filter what comes in and what goes out. Cisco assigned the flaw the identifier CVE-2026-76461, scored it 9.8 out of 10 for severity and labeled it critical. The company says it could let a remote attacker who has not logged in run commands with the highest level of privilege on the appliance's operating system. The listing also starts a clock for federal civilian agencies in the United States: CISA says its Binding Operational Directive 26-04 requires them to prioritize rapid remediation of catalog-listed flaws on publicly exposed assets, and that it encourages every other organization to do the same.
The company's advisory says the flaw affects Secure Email Gateway in both its physical and virtual forms, whatever the device's configuration. Two neighboring products, Secure Email and Web Manager, and Secure Web Appliance, are not affected. There are no workarounds, so upgrading is the only remedy on offer. The first fixed releases are 15.5.5-014, 16.0.4-302 and 16.5.0-780 for the corresponding release lines, and the advisory strongly recommends that customers move to 16.5.0-780.
Cisco says that its product security incident response team became aware of active exploitation in September 2026, that it has already upgraded every Cisco Secure Email Cloud device to the recommended release, and that it has contacted the customers whose cloud devices showed signs of possible compromise. Because an intruder holding that level of access can erase or hide the traces, the advisory tells administrators to check network and firewall logs kept outside the appliance rather than the device's own.
The flaw came to light while Cisco's support staff was working through a customer's case, the company says.
