EXPLOITED

Cisco Secure Email Gateway CVE-2026-76461 is CVSS 9.8. Crafted mail becomes root. CISA KEV due Sep 17.

Unauthenticated SQL injection in AsyncOS email parsing. No workaround. Fixed builds: 15.5.5-014, 16.0.4-302, 16.5.0-780. Federal KEV due: Sep 17. Victim count Undisclosed.

Sep 14, 2026 · 3 min read

Cisco’s Sep 14 advisory cisco-sa-esa-inj-2bLVGmhX tracks CVE-2026-76461 (CWE-89, bug CSCwu56234) at CVSS 9.8. Insufficient validation in Secure Email Gateway email parsing lets an unauthenticated remote attacker send a crafted message carrying malicious SQL; successful exploitation yields arbitrary SQL and root command execution on the underlying OS. Affects SEG physical and virtual, regardless of configuration. Cisco confirms Secure Email and Web Manager and Secure Web Appliance are not affected. No workarounds.

Fixed AsyncOS: 15.5.5-014 (15.5 and earlier), 16.0.4-302 (16.0), 16.5.0-780 (16.5) — Cisco strongly recommends migrating to 16.5.0-780. Cisco Secure Email Cloud is already on 16.5.0-780; Cisco says it has directly contacted Cloud customers where malicious activity was detected. On-prem: hunt mail_logs for suspicious SQL (example IOC pattern: COPY.*TO PROGRAM), cross-check external firewall/network logs, and assume post-root evidence may be wiped. Victim tally: count remains Undisclosed.

Cisco PSIRT became aware of active exploitation in September 2026. CISA added CVE-2026-76461 to KEV on Sep 14 with BOD 26-04 remediation due Sep 17 and forensic triage required. Underwrite from Cisco’s primary SQLi advisory + hardening companion release; CISA is the KEV clock. Patch on-prem now; Cloud customers Cisco contacted should renew credentials and crypto material on the appliance.

Sources