Cisco Secure Email Gateway vulnerability: CVE-2026-76461 #
Cisco has reported a vulnerability in their Secure Email Gateway product. This flaw allows remote, unauthenticated attackers to execute arbitrary code on the vulnerable system. Successful exploitation could allow complete system compromise.
This vulnerability has been assigned CVE-2026-76461 and is rated highly critical has a CVSS score of 9.8.
Note that there is evidence that this vulnerability is being actively exploited in the wild.
The following versions are affected
- 15.5.4-012 and earlier
- 16.0.3-044 and earlier
- 16.5.0 before 16.5.0-780
What is Cisco Secure Email Gateway? #
Cisco Secure Email Gateway is a secure email security appliance that allows organizations to handle email securely and potentially quarantine malicious or unwanted emails for analysis.
What is the impact? #
Successful exploitation of these vulnerabilities would allow an adversary to execute arbitrary code on the vulnerable host, potentially leading to complete system compromise.
Are updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- 15.5.5-014 and later
- 16.0.4-302 and later
- 16.5.0-780 and later
Find exposed Cisco Secure Email Gateway's with runZero #
From the Service inventory, use the following query to locate potentially vulnerable assets:
_asset.protocol:=http AND protocol:=http AND last.html.title:"Cisco%Gateway%C" AND NOT last.html.title:"Cloud"
December 2025 advisory: #
Cisco reported a vulnerability in their Secure Email Gateway product. This flaw allowed remote, unauthenticated attackers to execute arbitrary code on the vulnerable system. Successful exploitation could have allowed complete system compromise.
This vulnerability was assigned CVE-2025-20393, was rated highly critical, and had a CVSS score of 10.0.
Note that there was evidence that this vulnerability was being actively exploited in the wild.
All versions of Cisco Secure Email Gateway except Cisco Secure Email Gateway Cloud were affected.
What was the impact? #
Successful exploitation of these vulnerabilities would have allowed an adversary to execute arbitrary code on the vulnerable host, potentially leading to complete system compromise.
Were updates or workarounds available? #
There was no patched fixed version of this product available at the time. The vendor recommended disabling the "Spam Quarantine" feature and isolating potentially vulnerable systems behind network access controls.
How runZero users found potentially vulnerable systems #
From the Service inventory, users ran the following query to locate potentially vulnerable assets:
_asset.protocol:=http AND protocol:=http AND last.html.title:"Cisco%Gateway%C" AND NOT last.html.title:"Cloud"