Meyka Pro banner
Law and Government

Cisco Faces Twin Zero-Day Crisis as Two Critical Flaws Exploited in Active Attacks

September 18, 2026
06:41 AM
4 min read

Key Points

CVE-2026-76461 (CVSS 9.8) in Email Gateway exploited via malicious email, no auth required.

CVE-2026-76460 (CVSS 10.0) in ISE authentication bypass, unauthenticated API access grants root.

Both flaws allow attackers to tamper with logs and hide intrusion traces.

CSCO up 2.3% to AUD 110.24 on September 18, Meyka B+ grade with AUD 118.79 forecast.

Sentiment:NEGATIVE (-0.94)
Be the first to rate this article

Cisco Systems disclosed two critical security vulnerabilities being actively exploited by attackers as of September 2026. CVE-2026-76461 affects Secure Email Gateway with a CVSS score of 9.8, while CVE-2026-76460 targets Identity Services Engine with a perfect CVSS 10.0 rating. Both flaws allow unauthenticated remote attackers to execute commands with root privileges. The disclosures triggered emergency patching cycles and CISA listings.

Email gateway flaw spreads via malicious messages

The first vulnerability, CVE-2026-76461, resides in Cisco AsyncOS software for Secure Email Gateway. An attacker sends a specially crafted email through a vulnerable gateway and gains root access without authentication. Cisco’s PSIRT became aware of active exploitation in September 2026. The vulnerability was added to CISA’s Known Exploited Vulnerabilities catalog on the same day as disclosure, confirming it was exploited as a zero-day before the vendor announced it. Cisco recommends immediate upgrade to AsyncOS 16.5.0-780 on an emergency basis outside normal patching cycles.

ISE authentication bypass grants instant admin access

The second flaw, CVE-2026-76460, is an authentication bypass in Identity Services Engine and ISE Passive Identity Connector. An unauthenticated attacker sends a crafted request to an API endpoint with insufficient authentication controls and bypasses the web-based management interface entirely. The flaw received the maximum CVSS score of 10.0. Cisco disclosed it on September 17 after confirming active exploitation. Fixed versions span releases 3.1 Patch 12 through 3.5 Patch 4. No workarounds fully eliminate risk, though infrastructure access-control lists can limit exposure.

Recovery is difficult because attackers hide their tracks

Both vulnerabilities grant root-level access, allowing attackers to tamper with logs and conceal evidence of intrusion. Cisco advises organisations to check network and firewall logs held outside affected devices, not the appliances themselves. For ISE, admins must review access logs for suspicious usernames on every node in distributed deployments. For virtual appliances suspected of compromise, Cisco recommends reimaging nodes after preserving forensic evidence. Cisco Secure Email Cloud customers have already been upgraded to the patched version.

Cisco stock rises on security demand despite vulnerability risk

Cisco (CSCO) traded at AUD 110.24 on September 18, up 2.3% on the day. The stock has gained 62.8% over the past year and trades at a Meyka grade of B+. Eight analysts rate the stock as buy, with one hold rating and consensus at 3.0. Meyka’s 12-month forecast stands at AUD 118.79, suggesting limited upside from current levels. The twin vulnerabilities underscore the critical role of Cisco’s security products in enterprise infrastructure, though they also highlight execution risks in the company’s product security posture.

Final Thoughts

Cisco faces a rare dual crisis with two actively exploited zero-days in core security products. While emergency patches are available, organisations must act immediately to avoid root-level compromise. The incidents test Cisco’s credibility in network security at a moment when CSCO trades near resistance.

FAQs

Can attackers exploit these Cisco flaws without credentials?

Yes. Both CVE-2026-76461 and CVE-2026-76460 allow unauthenticated remote attackers to gain root access without logging in or user interaction.

What is the difference between the two Cisco vulnerabilities?

CVE-2026-76461 (CVSS 9.8) affects Email Gateway via malicious email. CVE-2026-76460 (CVSS 10.0) affects ISE via API endpoint. Both grant root access.

Are there workarounds for these Cisco flaws?

No full workarounds exist. Infrastructure access-control lists can limit ISE exposure. Patching is the only complete fix for both vulnerabilities.

How many organisations have been compromised by these flaws?

Cisco has not disclosed the total number. It contacted Secure Email Cloud customers whose appliances showed indicators of compromise and upgraded all cloud devices.

What should IT admins do if they suspect compromise?

Check network and firewall logs outside the appliance, review ISE access logs for suspicious usernames, and reimage virtual appliances if exploitation is suspected.

When did Cisco first learn of these attacks?

Cisco became aware of active exploitation of CVE-2026-76461 in September 2026. CVE-2026-76460 was disclosed on September 17 after active exploitation was confirmed.

Disclaimer:

The content shared by Meyka AI PTY LTD is solely for research and informational purposes.  Meyka is not a financial advisory service, and the information provided should not be considered investment or trading advice.

About Author

Author

Danny Kontos

Co Founder

Danny Kontos has been a stock investor since 2007 and co-founded Meyka in 2023. He keeps a small, focused portfolio and only moves when the numbers are hard to argue with. He has waited years on a single position before. Before Meyka, he ran a web hosting company and a mortgage lending platform, so he knows what a well-run business actually looks like under the hood. This article did not come from a news cycle. It came from someone who has been watching this space for a long time.

What brings you to Meyka?

Pick what interests you most and we will get you started.

I'm here to read news

Find more articles like this one

I'm here to research stocks

Ask Meyka Analyst about any stock

I'm here to track my Portfolio

Get daily updates and alerts (coming March 2026)