Cisco Secure Email Gateway (AsyncOS)
CVE-2026-76461: Cisco Secure Email Gateway SQL injection gives root from one email
An unauthenticated attacker can send a crafted email to a Secure Email Gateway and run commands as root (CVSS 9.8). Cisco says it is exploited in the wild, and CISA added it to KEV on September 14, 2026.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Secure Email Gateway (AsyncOS) 15.5 and earlier | 15.5.5-014 or later |
| Secure Email Gateway (AsyncOS) 16.0 | 16.0.4-302 or later |
| Secure Email Gateway (AsyncOS) 16.5 | 16.5.0-780 or later |
| Secure Email Cloud | Upgraded by Cisco to 16.5.0-780 |
| Secure Email and Web Manager, Secure Web Appliance | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
The email parsing logic in Cisco AsyncOS for Secure Email Gateway does not validate input properly (CWE-89, SQL injection). An unauthenticated attacker sends a crafted email containing SQL statements, and can then run commands as root on the appliance. No login and no user interaction are needed. Cisco scores it 9.8.
A mail gateway sits on the edge and sees all inbound and outbound mail. Root on it exposes message content, configuration and any credentials stored on the box.
Cisco says PSIRT became aware of active exploitation in September 2026, and it contacted Secure Email Cloud customers whose devices showed malicious activity. CISA added the CVE to KEV on September 14, 2026, and lists ransomware use as “Unknown”. No source we opened names the attacker, and none mentions a public proof of concept.
Am I affected?
Yes, if you run a physical or virtual Cisco Secure Email Gateway below the fixed releases in the table above. Cisco says it applies regardless of device configuration, so there is no setting to check. The CVE record lists releases from 13.0 to 16.0.
Not affected: Cisco Secure Email and Web Manager and Cisco Secure Web Appliance. Cisco has already upgraded Secure Email Cloud devices to 16.5.0-780.
What to do
- Upgrade now. Cisco says there are no workarounds. It strongly recommends that devices on releases earlier than 16.5 move to 16.5.0-780. Cisco’s upgrade paths:
- Web UI: System Administration > System Upgrade > Upgrade Options > Download and Install.
- CLI: run
upgrade, enterDOWNLOADINSTALL, then choose the release.
- Then check for compromise (see Detection). Cisco’s advisory says to search for indicators after upgrading.
- If you find indicators on a physical appliance, contact Cisco TAC. Cisco asks that remote access be enabled on suspected devices to support its investigation.
- If you find indicators on a virtual appliance, record forensics, deploy a new VM on a fixed release, rebuild the configuration, and renew credentials and cryptographic material that were on the appliance. Keep monitoring afterwards.
CISA’s KEV entry also points federal agencies to BOD 26-04 and its forensic triage requirements.
Detection
No indicators of compromise (IPs, hashes, file names or accounts) have been published by Cisco or the other sources we opened. Cisco’s checks are:
-
Search the mail logs for SQL. Run this against
mail_logsfrom the CLI. Any match may indicate malicious activity:grep -i "COPY.*TO PROGRAM" -
Check every node if the appliances are clustered.
-
Check logs held off the box. Root access can let an attacker remove or hide evidence. Look in network and firewall logs for unexpected uploads from the gateway to external IPs, or downloads from malicious IPs.
Cisco learned of exploitation in September 2026. Search back to at least the start of that month, and further if your gateway was unpatched and reachable earlier.
Sources
Page changelog
- Full analysis published.
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.