CVE-2026-76461
Cisco Secure Email Gateway SQL injection enables unauthenticated remote command execution (CVE-2026-76461)
Cisco Secure Email Gateway's AsyncOS email parsing has a critical SQL injection flaw (CVE-2026-76461). A remote, unauthenticated attacker can send a crafted email to execute commands with root privileges. CISA KEV and Cisco PSIRT confirm active exploitation; upgrade to a fixed release.
What happened
An unauthenticated remote attacker can exploit CVE-2026-76461 by sending a crafted email message containing malicious SQL statements through an affected Cisco Secure Email Gateway. The flaw is in AsyncOS email parsing validation. No credentials, special access, or user interaction are required. The CVSS 3.1 base score is 9.8 (Critical), reflecting a low-complexity network attack with high impact on confidentiality, integrity and availability.
A successful exploit allows the attacker to execute arbitrary SQL statements and then commands with root privileges on the underlying operating system. Cisco PSIRT has stated that in September 2026 it became aware of active exploitation of this vulnerability. CISA has listed the CVE in its Known Exploited Vulnerabilities catalogue, with a remediation due date of 17 September 2026.
Who is affected
The affected product is Cisco Secure Email Gateway running Cisco AsyncOS Software. The builds listed by Cisco are: 13.0.0-392, 13.0.5-007, 13.5.1-277, 13.5.4-038, 14.0.0-698, 14.2.0-620, 14.2.1-020 and 14.3.0-032. These gateways normally sit in the mail path and process messages from the internet, so organisations that accept external mail should treat these builds as vulnerable until upgraded. Cisco rates the vulnerability Critical.
What to do now
- Identify every Cisco Secure Email Gateway in your estate and confirm its AsyncOS build against the affected versions listed above.
- Upgrade affected devices to a fixed release: AsyncOS 15.5.5-014, 16.0.4-302 or 16.5.0-780. Cisco states there are no workarounds that address this vulnerability, so applying a fixed release is the definitive action.
- CISA's KEV entry lists a remediation due date of 17 September 2026 and requires applying mitigations in accordance with vendor instructions, following BOD 26-04 guidance, and evaluating each asset's internet exposure.
- If a fixed release cannot be applied, follow applicable BOD 26-04 guidance or discontinue use of the product where mitigations are unavailable.
How to detect it
Successful exploitation provides root-level command execution on the underlying operating system. Until patched, review each gateway for unexplained processes, new or modified administrative accounts, unexpected scheduled tasks, or unexpected outbound connections. Cisco has not provided specific indicators of compromise, so treat these as general checks rather than vendor-supplied detection content.
Beyond the patch
Because CISA KEV and Cisco PSIRT confirm active exploitation, the immediate priority is the upgrade; the secondary priority is detecting what may already have happened on an unpatched gateway. Spirity's Managed Detection & Response (MDR) monitors for post-exploitation activity such as unexpected root-level execution and unusual device behaviour, while an Incident Response Retainer gives you a pre-arranged team if you find signs of compromise. A Virtual CISO Services engagement can help structure the exposure review and apply the BOD 26-04 requirements across your internet-facing mail infrastructure.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Cisco Secure Email | 14.0.0-698 13.5.1-277 13.0.0-392 14.2.0-620 13.0.5-007 13.5.4-038 14.2.1-020 14.3.0-032 | No fixed version listed yet |