Cisco email gateways face active attacks with root access at stake

Cisco email gateways face active attacks with root access at stake. Enterprise email boundaries are at risk because attackers are actively exploiting Cisco Secure Email Gateway appliances.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 15th, 2026.

Enterprise email boundaries are at risk because attackers are actively exploiting Cisco Secure Email Gateway appliances. A crafted message can pass through an affected device and trigger commands with root privileges without any authentication. Cisco released software fixes, says there are no workarounds, and reported active exploitation in September 2026. CISA added the issue to its Known Exploited Vulnerabilities catalog on September 14th. A compromised gateway can give attackers a privileged position at the organization’s edge and a route toward persistence or data theft elsewhere. Root access also allows an intruder to alter local processes, delete logs, or interfere with evidence, so an investigation based only on the appliance may be inconclusive. Leaders should treat this as an emergency change and incident-response decision rather than routine maintenance. Defenders need to patch every affected node, review mail logs for suspicious S Q L statements, and cross-check firewall and outbound network telemetry. Apply Cisco’s fixed release immediately, and rebuild any on-premises gateway showing credible signs of compromise.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Cisco email gateways face active attacks with root access at stake
Broadcast by