Cisco Secure Email Gateway (AsyncOS)

CVE-2026-76461: Cisco Secure Email Gateway SQL injection gives root from one email

An unauthenticated attacker can send a crafted email to a Secure Email Gateway and run commands as root (CVSS 9.8). Cisco says it is exploited in the wild, and CISA added it to KEV on September 14, 2026.

Published Updated

ExploitedYes, in CISA KEVAdded 14 Sept 2026
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 9.8
EPSS28%Chance of exploitation in 30 days
Public exploitNot known
FixAvailable

Affected and fixed versions

Product / branchFixed in
Secure Email Gateway (AsyncOS) 15.5 and earlier15.5.5-014 or later
Secure Email Gateway (AsyncOS) 16.016.0.4-302 or later
Secure Email Gateway (AsyncOS) 16.516.5.0-780 or later
Secure Email CloudUpgraded by Cisco to 16.5.0-780
Secure Email and Web Manager, Secure Web ApplianceNot affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

The email parsing logic in Cisco AsyncOS for Secure Email Gateway does not validate input properly (CWE-89, SQL injection). An unauthenticated attacker sends a crafted email containing SQL statements, and can then run commands as root on the appliance. No login and no user interaction are needed. Cisco scores it 9.8.

A mail gateway sits on the edge and sees all inbound and outbound mail. Root on it exposes message content, configuration and any credentials stored on the box.

Cisco says PSIRT became aware of active exploitation in September 2026, and it contacted Secure Email Cloud customers whose devices showed malicious activity. CISA added the CVE to KEV on September 14, 2026, and lists ransomware use as “Unknown”. No source we opened names the attacker, and none mentions a public proof of concept.

Am I affected?

Yes, if you run a physical or virtual Cisco Secure Email Gateway below the fixed releases in the table above. Cisco says it applies regardless of device configuration, so there is no setting to check. The CVE record lists releases from 13.0 to 16.0.

Not affected: Cisco Secure Email and Web Manager and Cisco Secure Web Appliance. Cisco has already upgraded Secure Email Cloud devices to 16.5.0-780.

What to do

  1. Upgrade now. Cisco says there are no workarounds. It strongly recommends that devices on releases earlier than 16.5 move to 16.5.0-780. Cisco’s upgrade paths:
    • Web UI: System Administration > System Upgrade > Upgrade Options > Download and Install.
    • CLI: run upgrade, enter DOWNLOADINSTALL, then choose the release.
  2. Then check for compromise (see Detection). Cisco’s advisory says to search for indicators after upgrading.
  3. If you find indicators on a physical appliance, contact Cisco TAC. Cisco asks that remote access be enabled on suspected devices to support its investigation.
  4. If you find indicators on a virtual appliance, record forensics, deploy a new VM on a fixed release, rebuild the configuration, and renew credentials and cryptographic material that were on the appliance. Keep monitoring afterwards.

CISA’s KEV entry also points federal agencies to BOD 26-04 and its forensic triage requirements.

Detection

No indicators of compromise (IPs, hashes, file names or accounts) have been published by Cisco or the other sources we opened. Cisco’s checks are:

  • Search the mail logs for SQL. Run this against mail_logs from the CLI. Any match may indicate malicious activity:

    grep -i "COPY.*TO PROGRAM"
    
  • Check every node if the appliances are clustered.

  • Check logs held off the box. Root access can let an attacker remove or hide evidence. Look in network and firewall logs for unexpected uploads from the gateway to external IPs, or downloads from malicious IPs.

Cisco learned of exploitation in September 2026. Search back to at least the start of that month, and further if your gateway was unpatched and reachable earlier.

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.