Cisco Secure Email Gateway is facing active exploitation of a critical vulnerability, CVE-2026-76461, reported as a root command execution issue. SecurityWeek and The Hacker News both say the flaw allows an unauthenticated remote attacker to exploit insufficient validation in the gateway’s email parsing logic. Successful exploitation enables arbitrary command execution on the underlying operating system with root privileges.

Both outlets describe the impact as remote takeover of the device at the highest privilege level. The Hacker News adds that Cisco assigns the issue a very high severity, with a CVSS score of 9.8/10.0, and frames it as a parsing validation problem that can be triggered without authentication. While SecurityWeek emphasizes that exploitation is already occurring “in the wild,” both sources align on the core technical details: remote, unauthenticated access and root-level command execution.

The differing emphasis is mainly on reporting style and additional scoring context; neither outlet contradicts the basic scenario of a critical email gateway flaw being actively used to gain full system control.