Cisco has disclosed that two critical zero-day vulnerabilities—one in its Secure Email Gateway (SEG) product and another in its Secure Firewall Management Center (FMC)—are being actively exploited in the wild. These flaws allow attackers to operate without credentials, execute arbitrary code at the root level, and potentially mount severe attacks including ransomware deployment.
Zero-Day in Secure Email Gateway: CVE-2026-76461
First is CVE-2026-76461, a vulnerability in Cisco’s AsyncOS for its Secure Email Gateway appliances. The bug stems from flaws in email parsing logic, enabling unauthenticated remote attackers to send specially crafted emails containing SQL statements that can trigger arbitrary command execution as root. Cisco’s PSIRT confirmed that exploitation of this flaw began in September 2026. The Common Vulnerability Scoring System (CVSS) score for this issue is 9.8 out of 10—one step below critical. Affected units include both physical and virtual appliances. A patch has been released, and the vulnerability has been added to the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog as of September 14, 2026.
FMC Authentication Bypass: CVE-2026-20079 & Chained Exploitation
The second issue, CVE-2026-20079, is an authentication bypass affecting Cisco Secure Firewall Management Center. Initially disclosed in March 2026 with no known active exploitation, Cisco now confirms attackers began abusing it in August. By sending crafted HTTP requests to the device’s web interface, unauthenticated actors can gain root access. Notably, this flaw has been chained with another vulnerability—CVE-2026-20316 (which involves static credentials for a low-privileged account)—to elevate access and facilitate broader abuse. Exploited systems have been used to steal credentials, deploy the Qilin ransomware, and even install variants of Cyclops Blink malware.
Urgent Actions and Impacts
Both vulnerabilities are within the highest severity class, with CVE-2026-20079 rated critical (CVSS 10.0). Cisco emphasizes there are no workarounds for either issue—patching is the only path to security. For CVE-2026-20079, the advisory notes that installing hotfixes prevents future exploitation but won’t clean up hosts already compromised. Similarly, CVE-2026-76461 requires a full update to address the root cause.
U.S. federal agencies are under specific pressure. Following the CVE-2026-20079 disclosure, CISA added it to the KEV catalog and ordered civilian federal entities to patch affected systems by September 12, 2026. For CVE-2026-76461, inclusion in the KEV list came September 14, triggering similar compliance expectations. Organizations running interfaces exposed to the internet are especially at risk and encouraged to restrict remote access to these management tools immediately.
Why this matters: A management tool like FMC—designed to centrally control firewalls—gives attackers the potential to breach entire network defenses if compromised. An email gateway handles incoming mail traffic, so its compromise can lead not only to malware delivery, but also to lateral movement across systems. The combination raises unusually high stakes for enterprises, especially those with limited segmentation or audit visibility.
Longer term, this attack pattern illustrates a shift in zero-day exploitation: chaining multiple vulnerabilities and targeting core management components. Security teams should not merely patch; they need to validate integrity of their perimeters, check for signs of credential theft or ransomware deployment, and assume that once one tool is compromised, trust boundaries may already have been violated.
What to watch next: Future advisory updates detailing indicators of compromise, whether threat actors associated with these exploits align with known ransomware gangs or APTs, and how exposed systems globally are being leveraged. For now, immediate patching, network hardening, and monitoring activity logs for anomalies related to /var/tmp/license.tmp or unexpected root-level activity are essential.