Cisco Secure Email Gateway SQL Injection – Actively Exploited
Cisco Secure Email Gateway SQL Injection – Actively Exploited
Summary
Cisco disclosed a critical, unauthenticated SQL injection vulnerability (CVE-2026-76461, CVSS 3.1 9.8) in AsyncOS Software for Cisco Secure Email Gateway that lets a remote attacker execute arbitrary commands with root privileges on the underlying operating system by sending a specially crafted email message. Cisco PSIRT reports it is aware of active exploitation, and CISA has added the CVE to the Known Exploited Vulnerabilities (KEV) catalog with an expedited BOD-26-04 forensic-triage deadline of 2026-09-17. No workaround exists; Cisco has published fixed releases.
Affected Systems and/or Applications
Vulnerable: Cisco Secure Email Gateway (physical and virtual appliances)
- Release 15.5 and earlier
- Release 16.0
- Release 16.5
Not vulnerable: Secure Email and Web Manager; Secure Web Appliance.
Technical Details
Vulnerability Mechanism
An unauthenticated, remote attacker can embed malicious SQL statements in an email message processed by an affected Secure Email Gateway device, resulting in SQL injection that escalates to arbitrary OS command execution with root privileges. The flaw is tracked as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).
Observed Exploitation Path
In September 2026, Cisco PSIRT became aware of active exploitation of this vulnerability. Some Cisco Secure Email Cloud devices showed indicators of possible compromise; Cisco directly contacted affected customers and has already upgraded all Cisco Secure Email Cloud devices to fixed releases. CISA independently corroborated active/known exploitation by adding CVE-2026-76461 to the KEV catalog on 2026-09-14 with a 2026-09-17 remediation due date.
Key Points
- CVSS 3.1 base score 9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
- CISA KEV-listed with CWE-89, added 2026-09-14, due 2026-09-17, forensic triage required per BOD-26-04.
- No workaround is available; upgrading is the only remediation.
Mitigation
Immediate Actions for Self-Hosted Instances
Limit Exposure
Cisco has not published a workaround or mitigating configuration for this vulnerability.
Patch/Upgrade
Upgrade to a fixed release; Cisco recommends migrating to Release 16.5.0-780:
Threat Hunting
Cisco recommends monitoring mail_logs for suspicious SQL statements containing patterns such as COPY.*TO PROGRAM, and notes that evidence of exploitation may have been removed by threat actors given the root-level access obtained.
What the Cyber Fusion Center is Doing
The CFC is monitoring the situation and analyzing the case to identify potential threat-hunting campaigns. This advisory will be updated if required.
IDs
- CVE-2026-76461
- CWE-89
- Vendor Advisory: cisco-sa-esa-inj-2bLVGmhX
- Qualys QID: 317880
References
- Cisco Security Advisory (cisco-sa-esa-inj-2bLVGmhX): https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- FIRST EPSS: https://api.first.org/data/v1/epss?cve=CVE-2026-76461
- Qualys QID 317880: https://www.qualys.com/vulnerability-detection-pipeline
.webp)

.avif)


.webp)

