# Cisco says email-gateway zero-day was exploited before patch

_Published Tuesday, September 15, 2026 at 6:19 PM EDT · Security · Latest · Tier 1 — Major_

![Cisco says email-gateway zero-day was exploited before patch — Primary](https://cyberscoop.com/wp-content/uploads/sites/3/2023/10/GettyImages-1127349614.jpg)

Cisco disclosed and patched CVE-2026-76461, a critical zero-day in Cisco Secure Email Gateway that it says was exploited before disclosure.

The flaw affects Cisco AsyncOS Software and lets unauthenticated remote attackers execute commands with root privileges on vulnerable systems. Cisco said it contacted Cisco Secure Email Cloud customers where it identified possible compromise indicators and deployed mitigations within its managed environment. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.

Cisco released indicators of compromise, though attackers may be able to hide or remove traces.

## Sources

- [CyberScoop](https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/)

---
Canonical: https://techandbusiness.org/newswire/ilbyofrApqD_jwo9uXAvOC
Published: 2026-09-15T22:19:31.892Z
Story chronology: 2026-09-15T15:44:41.000Z
Retrieved: 2026-09-16T00:33:10.151Z
Publisher: Tech & Business (techandbusiness.org)
