Cisco patches CVE-2026-76461, a Secure Email Gateway zero-day exploited for root command execution
CVE-2026-76461 (CVSS 9.8), a zero-day in the AsyncOS email parsing of Cisco Secure Email Gateway, has been exploited since September 2026 to turn a SQL injection into root command execution. Cisco offers no workaround and CISA requires a fix by September 17, 2026: patch your Secure Email Gateway appliances now.