Skip to content
See the World Through ScienceA project of ALLATRA

U.S. Cyber Agency Says a Cisco Email Flaw Is Already Being Exploited

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Two rack-mounted Cisco network switches in a data center, their ports filled with patch cables, in black and white.
Rack-mounted Cisco network switches in a data center (illustrative)."two Cisco 3750s" by Bob Mical, via flickr, BY-NC · BY-NC

The U.S. Cybersecurity and Infrastructure Security Agency added a flaw in Cisco's Secure Email Gateway to its Known Exploited Vulnerabilities catalog on Sept. 14, 2026, saying it had evidence that attackers are already using it. Cisco published a fix the same day.

That gateway is the appliance many organizations put in front of their corporate mail to filter what comes in and what goes out. Cisco assigned the flaw the identifier CVE-2026-76461, scored it 9.8 out of 10 for severity and labeled it critical. The company says it could let a remote attacker who has not logged in run commands with the highest level of privilege on the appliance's operating system. The listing also starts a clock for federal civilian agencies in the United States: CISA says its Binding Operational Directive 26-04 requires them to prioritize rapid remediation of catalog-listed flaws on publicly exposed assets, and that it encourages every other organization to do the same.

The company's advisory says the flaw affects Secure Email Gateway in both its physical and virtual forms, whatever the device's configuration. Two neighboring products, Secure Email and Web Manager, and Secure Web Appliance, are not affected. There are no workarounds, so upgrading is the only remedy on offer. The first fixed releases are 15.5.5-014, 16.0.4-302 and 16.5.0-780 for the corresponding release lines, and the advisory strongly recommends that customers move to 16.5.0-780.

Cisco says that its product security incident response team became aware of active exploitation in September 2026, that it has already upgraded every Cisco Secure Email Cloud device to the recommended release, and that it has contacted the customers whose cloud devices showed signs of possible compromise. Because an intruder holding that level of access can erase or hide the traces, the advisory tells administrators to check network and firewall logs kept outside the appliance rather than the device's own.

The flaw came to light while Cisco's support staff was working through a customer's case, the company says.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

U.S. Cyber Agency Says a Cisco Email Flaw Is Already Being Exploited

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.