Skip to main content
CiscoSecurity incident

Cisco email security boxes can be rooted by... an email

What happened

Cisco's Secure Email Gateway appliances have a critical vulnerability (CVE-2026-76461) that allows attackers to gain root access via a malicious email, and the flaw is being actively exploited.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

security Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly what you want from the box tasked with keeping nasty emails out. Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Assistance Center support case. Signs suggest at least some Cisco cloud customers were caught up in the attacks. Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise. It is now...

Keep reading with a free account

The rest of this article, and every signal for Cisco, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
Cisco Secure Email Gateway

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
A critical flaw, tracked as CVE-2026-76461 with a 9.8 CVSS score, in the AsyncOS software allows an unauthenticated attacker to send a malicious email through a vulnerable gateway and run commands as root. The vulnerability is being...

Topics and mentions

Product tags

  • security
  • online technology
  • general technology

Extraction

Confidence
100%
Detected
Sep 15, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Cisco and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Cisco this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/7cb7b60a-3ddf-7c26-b52b-5ff33315a264 returns this record as JSON. POST /v1/companies/enrich returns every signal for cisco.com.

{
  "signal_id": "7cb7b60a-3ddf-7c26-b52b-5ff33315a264",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-15T16:01:00+00:00",
  "company": {
    "name": "Cisco",
    "domain": "cisco.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604",
    "title": "Cisco email security boxes can be rooted by... an email",
    "excerpt": "security Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds , so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly what you want from the box tasked with keeping nasty emails out. Cisco's Product Security Incident Response Team said it became aware of active exploitation in September, although the networking giant hasn't said who is behind the attacks, how long they have been going on, or how many organizations have been compromised. Cisco uncovered the bug while resolving a Technical Assistance Center support case. Signs suggest at least some Cisco cloud customers were caught up in the attacks. Cisco said it investigated devices belonging to its Secure Email Cloud service and directly contacted customers whose appliances showed indicators of possible compromise. It is now...",
    "product": "Cisco Secure Email Gateway",
    "summary": "Cisco's Secure Email Gateway appliances have a critical vulnerability (CVE-2026-76461) that allows attackers to gain root access via a malicious email, and the flaw is being actively exploited.",
    "planning": false,
    "image_url": "https://image.theregister.com/260832.jpg?imageId=260832&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 1,
    "product_data": {
      "name": "Cisco Secure Email Gateway",
      "full_text": "Cisco Secure Email Gateway",
      "fuzzy_match": false
    },
    "product_tags": [
      "security",
      "online_technology",
      "general_technology"
    ],
    "published_at": "2026-09-15T16:01:00Z",
    "vulnerability": "A critical flaw, tracked as CVE-2026-76461 with a 9.8 CVSS score, in the AsyncOS software allows an unauthenticated attacker to send a malicious email through a vulnerable gateway and run commands as root. The vulnerability is being actively exploited.",
    "article_sentence": "Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.