Actively Exploited Cisco Secure Email Gateway SQLi-to-Root RCE(CVE-2026-76461)

Share:

Cisco has patched an actively exploited zero-day in its Secure Email Gateway that lets an
unauthenticated, remote attacker take full control of the appliance simply by sending a crafted email.
Tracked as CVE-2026-76461 and rated critical (CVSS 9.8), the flaw is a SQL injection in the email
parsing logic of Cisco AsyncOS: a malicious email carrying SQL statements is processed by the device,
leading to arbitrary SQL execution and command execution with root privileges on the underlying
operating system. It affects both physical and virtual Secure Email Gateway appliances regardless of
configuration, there are no workarounds, and Cisco has confirmed exploitation in the wild while CISA
has added it to its Known Exploited Vulnerabilities catalog with a 17 September patch deadline for
federal agencies. Because a successful attack grants root and lets intruders erase evidence,
organisations should patch immediately and hunt for signs of compromise both on the appliance and in
external network logs.

1. Vulnerability Details

CVE ID – CVE-2026-76461 (Cisco advisory cisco-sa-esa-inj-2bLVGmhX)
CVSS SCORE -9.8 (CVSS:3.1, Cisco; Critical) AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EXPLOIT STATUS – Actively exploited; Cisco PSIRT became aware of exploitation in September 2026. Added to
the CISA KEV catalog on 14 Sep 2026 with a federal patch deadline of 17 Sep. No workarounds; fixed software available.

CVE-2026-76461 is a SQL injection vulnerability (CWE-89) caused by insufficient validation in the email-parsing logic of
Cisco AsyncOS for Secure Email Gateway. An unauthenticated, remote attacker sends a crafted email message
containing malicious SQL statements through an affected device; successful exploitation executes arbitrary SQL and
leads to command execution with root privileges on the underlying operating system. The flaw was found during a Cisco
TAC support case.

2. Affected Products & Fixed Versions

ComponentVulnerable VersionsFixed Build
Cisco Secure Email Gateway (physical & virtual, any config) – AsyncOS 15.5 and earlier15.5 and earlier15.5.5-0141
Cisco Secure Email Gateway – AsyncOS 16.016.016.0.4-3021
Cisco Secure Email Gateway – AsyncOS 16.516.516.5.0-780 (recommended)

3. Exploitation & Exposure

A patch is available, exploitation is confirmed, and evidence may be hidden by attackers who gain root.

  • Active exploitation and KEV: Cisco PSIRT confirmed active exploitation in September 2026, and CISA added CVE 2026-76461 to its Known Exploited Vulnerabilities catalog on 14 Sep with a 17 Sep federal patch deadline. Shadowserver tracks more than 400 internet-exposed Secure Email Gateway appliances.
  • Evidence tampering risk: Because a successful exploit runs with root privileges, attackers may remove or hide on device indicators. Cisco advises cross-checking external network and firewall logs for suspicious activity such as unexpected uploads to external IPs or downloads from malicious IPs.
  • Not affected / related fixes: Cisco Secure Email and Web Manager and Cisco Secure Web Appliance are not affected. On the same day Cisco patched four other critical SEG/SEWM flaws (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353 and CVE-2026-76443), with no evidence of exploitation.

4. Recommendations

  • Upgrade all Cisco Secure Email Gateway appliances (physical and virtual) immediately to a fixed AsyncOS release: 15.5.5-0141 (for 15.5 and earlier), 16.0.4-3021 (for 16.0) or 16.5.0-780 (for 16.5). Cisco recommends migrating to 16.5.0-780. There are no workarounds, and CISA requires federal agencies to patch by 17 September.
  • Hunt for exploitation: grep each cluster device’s mail_logs for suspicious SQL such as ‘COPY … TO PROGRAM’ (any match may indicate compromise) and deploy Snort rules 67109-67110. Because a successful exploit runs as root and can erase on-device evidence, also cross-check external network and firewall logs for unexpected uploads or downloads to and from external or malicious IP addresses.
  • Treat suspected-compromised virtual appliances per Cisco’s guidance: preserve forensic information first, then deploy a new virtual machine on a fixed release, rebuild the configuration, and renew all credentials and cryptographic material; for physical appliances, engage Cisco TAC.
  • If you use Cisco Secure Email Cloud, note Cisco has upgraded those instances to 16.5.0-780 and contacted affected customers; if you were contacted, renew credentials and cryptographic material and restrict appliance access.
  • Reduce exposure: prevent internet access to the appliance where possible or restrict it to known, trusted hosts, separate mail and management interfaces, place the appliance behind a firewall, disable unneeded services such as HTTP and FTP, and disable HTTP for the administrator portal.
  • Apply the four other critical Secure Email Gateway and Secure Email and Web Manager fixes released the same day (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353 and CVE-2026-76443); Cisco reports no known exploitation of these, but they are rated critical.

5. Sources

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa
    inj-2bLVGmhX
  • https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461
  • https://nvd.nist.gov/vuln/detail/CVE-2026-76461

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Contact Us
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.