INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Cisco Zero-Day Exploited in Email Gateways

| 2026-09-17 21:03 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The latest zero-day vulnerability, CVE-2026-76460, has been exploited before Cisco disclosed and patched the vulnerability on Wednesday. Researchers haven't attributed attacks involving this exploit to any known group or threat actor yet, but Landon Rice noted that Cisco ISE vulnerabilities are a recurring target. Multiple vulnerabilities affecting the Cisco product have also been exploited since June 2025, including CVE-2025-20337 and CVE-2025-20281. The vulnerability in question allows remote attackers to bypass authentication and gain full control of affected devices through an API exploit in Cisco Identity Services Engine (ISE). This has been added to the U.S. Cybersecurity and Infrastructure Security Agency's known exploited vulnerabilities catalog, following a similar disclosure last month for CVE-2026-76461.
Technical Mitigations AI-generated
* Implement a secure email filtering system to block malicious emails containing SQL statements, and consider using an email security service that can detect and prevent such attacks. * Regularly update and patch Cisco Secure Email Gateway software to ensure it has the latest security patches and fixes for CVE-2026-76461. * Use a web application firewall (WAF) or intrusion detection system (IDS) to monitor incoming traffic and block suspicious activity, including attempts to exploit CVE-2026-76460. * Configure network segmentation and access controls to limit lateral movement in case of an attack, using techniques such as IPsec, VLANs, or DNSSEC to restrict access to sensitive areas. * Consider implementing a content security policy (CSP) that enforces strict filtering rules for emails containing malicious code or scripts, reducing the risk of exploitation by attackers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

158.94.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-20337CVE-2025-20337 CVE-2026-76441CVE-2026-76441 CVE-2026-76443CVE-2026-76443 CVE-2026-76460CVE-2026-76460 CVE-2026-20353CVE-2026-20353 CVE-2026-76440CVE-2026-76440 CVE-2026-76461CVE-2026-76461 CVE-2025-20281CVE-2025-20281 CVE-2025-20393CVE-2025-20393
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment
Incident Timeline
‎November 2021
Ransomware gangs exploited a recently discovered Cisco vulnerability in email gateways starting from November 2021.
tactic Ransomware
general_metric 98 Cisco vulnerabilities
‎June 2025
Threat actors exploited a zero-day vulnerability in Cisco email gateways starting from June 2025.
vulnerability CVE-2025-20337
vulnerability CVE-2025-20281
organisation CVE-2025
‎the summer of 2025
Threat actors exploited a zero-day vulnerability in Cisco email gateways.
‎November 2025
Threat actors exploited a maximum-severity Cisco AsyncOS vulnerability (CVE-2025-20393) in SEG and SEWM email gateways.
vulnerability CVE-2025-20393
organisation SEG
‎late August 2026
Threat actors exploited a previously unknown zero-day vulnerability in Cisco's email gateways.
‎August 26
Threat actors exploited a previously unknown zero-day vulnerability in Cisco email gateways.
‎August 28, 2026
Threat actors exploited a previously unknown zero-day vulnerability in Cisco email gateways.
‎September 14, 2026
Threat actors exploited a zero-day vulnerability in Cisco Secure Email Gateway.
‎September 14
Threat actors exploited a zero-day vulnerability in Cisco email gateways.
vulnerability CVE-2026-76461
attribution KEV
target_region United States
attribution Known Exploited Vulnerability
general_metric 76461 CVE-2026
‎September 15, 2026
Threat actors used a previously unknown vulnerability in Cisco's Secure Email Gateway to gain root access through malicious emails.
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
‎Sep 15, 2026
Threat actors exploited a previously unknown vulnerability in Cisco email gateways.
‎September 17, 2026
Threat actors exploited a zero-day vulnerability in Cisco email gateways to gain unauthorized access.
vulnerability CVE-2026-76461
tactic T1588.006 - Vulnerabilities
attribution KEV
general_metric 76461 CVE-2026
attribution Known Exploited
attribution FCEB
attribution Federal Civilian Executive Branch
‎September 17
Threat actors exploited a zero-day vulnerability in Cisco's email gateways.
vulnerability CVE-2026-76461
attribution KEV
target_region United States
attribution Known Exploited Vulnerability
general_metric 76461 CVE-2026
tactic T1588.006 - Vulnerabilities
attribution Known Exploited
‎2026/09/17
An attacker could exploit the Cisco Secure Email Gateway flaw by sending a crafted email message that contains malicious SQL statements through an affected device.
organisation CVE-2026-76460
organisation CVE-2026-76461
organisation CVE-2026
organisation Cisco Secure Email
organisation Secure Email Gateway
organisation CVSS
organisation API of Cisco Identity Services Engine
organisation CyberScoop
organisation Enables Root Command Execution
organisation SQL
organisation Cisco Secure Email Gateway
infrastructure 15.5
infrastructure 15.5.5-0141
infrastructure 16.0
infrastructure 16.0.4-302
infrastructure 16.5
infrastructure 16.5.0-780
organisation Counter Threat Unit
organisation Cisco
organisation SecurityAffairs
organisation Cisco Secure Email Cloud
organisation VulnCheck
organisation CVE-2026-76440
organisation CVE-2026-76441
organisation IP
organisation NFL
organisation CHANEL
organisation Vulnerability / Network Security
organisation Secure Email
organisation Large-Scale Credential Attacks Target Fortinet
organisation Fortinet VPN
‎September 2026
Threat actors exploited a zero-day vulnerability in Cisco email gateways.
Tactical Metrics
Metrics
infrastructure
‎15.5
Software Version
Metrics
infrastructure
‎15.5.5-0141
Software Version
Metrics
infrastructure
‎16.0
Software Version
Metrics
infrastructure
‎16.0.4-302
Software Version
Metrics
infrastructure
‎16.5
Software Version
Metrics
infrastructure
‎16.5.0-780
Software Version