CVE-2026-76461
September 15, 2026
·
0
Minutes Read

Cisco Secure Email Gateway SQL Injection – Actively Exploited

Advisory
Security Advisory
September 15, 2026
·
0
Minutes Read

Cisco Secure Email Gateway SQL Injection – Actively Exploited

Advisory
Security Advisory
September 15, 2026
·
0
Minutes Read
Kudelski Security Team
Find out more
table of contents
Share on
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Summary

Cisco disclosed a critical, unauthenticated SQL injection vulnerability (CVE-2026-76461, CVSS 3.1 9.8) in AsyncOS Software for Cisco Secure Email Gateway that lets a remote attacker execute arbitrary commands with root privileges on the underlying operating system by sending a specially crafted email message. Cisco PSIRT reports it is aware of active exploitation, and CISA has added the CVE to the Known Exploited Vulnerabilities (KEV) catalog with an expedited BOD-26-04 forensic-triage deadline of 2026-09-17. No workaround exists; Cisco has published fixed releases.

Affected Systems and/or Applications

Vulnerable: Cisco Secure Email Gateway (physical and virtual appliances)

  • Release 15.5 and earlier
  • Release 16.0
  • Release 16.5

Not vulnerable: Secure Email and Web Manager; Secure Web Appliance.

Technical Details

Vulnerability Mechanism

An unauthenticated, remote attacker can embed malicious SQL statements in an email message processed by an affected Secure Email Gateway device, resulting in SQL injection that escalates to arbitrary OS command execution with root privileges. The flaw is tracked as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).

Observed Exploitation Path

In September 2026, Cisco PSIRT became aware of active exploitation of this vulnerability. Some Cisco Secure Email Cloud devices showed indicators of possible compromise; Cisco directly contacted affected customers and has already upgraded all Cisco Secure Email Cloud devices to fixed releases. CISA independently corroborated active/known exploitation by adding CVE-2026-76461 to the KEV catalog on 2026-09-14 with a 2026-09-17 remediation due date.

Key Points

  • CVSS 3.1 base score 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
  • CISA KEV-listed with CWE-89, added 2026-09-14, due 2026-09-17, forensic triage required per BOD-26-04.
  • No workaround is available; upgrading is the only remediation.

Mitigation

Immediate Actions for Self-Hosted Instances

Limit Exposure

Cisco has not published a workaround or mitigating configuration for this vulnerability.

Patch/Upgrade

Upgrade to a fixed release; Cisco recommends migrating to Release 16.5.0-780:

Release First Fixed Version
15.5 and earlier 15.5.5-0141
16.0 16.0.4-3021
16.5 16.5.0-780

Threat Hunting

Cisco recommends monitoring mail_logs for suspicious SQL statements containing patterns such as COPY.*TO PROGRAM, and notes that evidence of exploitation may have been removed by threat actors given the root-level access obtained.

What the Cyber Fusion Center is Doing

The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.

IDs

  • CVE-2026-76461
  • CWE-89
  • Vendor Advisory: cisco-sa-esa-inj-2bLVGmhX
  • Qualys QID: 317880

References

Related Post