CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Is Being Exploited—Update and Check for Compromise
A specially crafted email is all it takes: via an SQL injection in AsyncOS, attackers can execute commands with root privileges on Cisco Secure Email Gateway (CVE-2026-76461, CVSS 9.8). The vulnerability is being exploited, and no workaround is available. Updating to a fixed version and checking for compromise are required.
On September 14, 2026, Cisco published advisory cisco-sa-esa-inj-2bLVGmhX regarding a critical vulnerability in AsyncOS for Cisco Secure Email Gateway. A specially crafted email processed by the gateway contains SQL statements that are executed due to insufficient validation in the processing logic; this results in arbitrary command execution with root privileges on the underlying operating system. No authentication is required. The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco learned of active exploitation in September 2026; the U.S. agency CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on September 14, 2026. Updates are available, and Cisco states that no workaround exists.
Support with updating and checking
If you need help securing, checking for compromise, or updating Cisco Secure Email Gateway, please use the contact form on adeptio.ch. I can also get back to you at short notice.
Key points at a glance
| Feature | Details |
|---|---|
| Advisory | cisco-sa-esa-inj-2bLVGmhX, published September 14, 2026, revision 1.1 dated September 17, 2026 |
| CVE | CVE-2026-76461 (Cisco Bug ID CSCwu56234) |
| Severity | CVSS 3.1: 9.8 (critical), AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Vulnerability type | SQL injection (CWE-89) in AsyncOS email processing, with command execution as root |
| Prerequisite | no authentication; a specially crafted email passing through the gateway |
| Affected | Cisco Secure Email Gateway, physical and virtual, regardless of configuration |
| Not affected | Secure Email and Web Manager, Secure Web Appliance |
| Fixed versions | 15.5.5-014, 16.0.4-302, 16.5.0-780 |
| Exploitation | confirmed by Cisco (known since September 2026); CISA KEV since September 14, 2026 |
| CISA deadline for U.S. federal agencies | September 17, 2026 |
| Workaround | none |
Affected versions and updates
| Version branch | Affected | Fixed in |
|---|---|---|
| AsyncOS 15.5 and earlier | all versions before 15.5.5-014 | 15.5.5-014 |
| AsyncOS 16.0 | all versions before 16.0.4-302 | 16.0.4-302 |
| AsyncOS 16.5 | all versions before 16.5.0-780 | 16.5.0-780 |
Cisco explicitly recommends migrating systems running a version earlier than 16.5 to 16.5.0-780. According to Cisco, it has already updated all devices for Cisco Secure Email Cloud customers to 16.5.0-780.
The CLI displays the installed version with:
version
What is known about the exploitation
Cisco states in the advisory that Cisco PSIRT learned of active exploitation in September 2026. The vulnerability was discovered while handling a support case in Cisco TAC. Secure Email Cloud customers whose devices Cisco found to have malicious activity were contacted directly.
Neither Cisco nor CISA provides details on the attacker, the number of affected organizations, or the precise start of the attacks (as of October 6, 2026). CISA lists whether the vulnerability is used in ransomware campaigns as unknown in the KEV entry. The three-day deadline between inclusion in the KEV Catalog and remediation is short; in addition to the vendor’s measures, CISA explicitly requires U.S. federal agencies to conduct forensic triage.
The attack path is the normal mail flow: the specially crafted message merely needs to pass through the gateway. Blocking the management interface from the internet therefore does not prevent exploitation.
Immediate measures
-
Determine the version with
versionin the CLI and compare it with the table above. For clusters, this applies to every member. -
Check for compromise before updating (see the next section) and preserve logs. If compromise is suspected, follow Cisco’s recommendations for rebuilding rather than merely updating.
-
Install the update: If there is no indication of exploitation, Cisco recommends updating to a fixed version and migrating systems earlier than 16.5 to 16.5.0-780.
-
Reduce exposure: In the advisory, Cisco lists general hardening measures, including restricting internet access, placing mail and management functions on separate interfaces, operating the appliance behind a firewall, disabling HTTP for the management interface, and disabling unnecessary services. These measures reduce the attack surface but do not close the vulnerability in the mail flow.
-
Monitor the advisory: Cisco updates the advisory when new information becomes available, most recently on September 17, 2026, with the note about clusters.
Checking for compromise
Cisco recommends checking the mail logs (default name mail_logs) for suspicious SQL statements and provides the following non-exhaustive example:
grep -i "COPY.*TO PROGRAM" mail_logs
If the device is part of a cluster, Cisco says the logs of every cluster member must be checked. An empty search result does not prove that a system is clean: an attacker with root privileges can remove traces from the device. Cisco therefore recommends correlating network and firewall logs outside the device, especially for unexpected uploads from the gateway to external IP addresses and downloads from malicious IP addresses. Cisco does not provide specific IP addresses, file names, or hash values in the advisory.
An update does not remove changes already made by an attacker. In the event of suspected compromise, Cisco recommends the following depending on the deployment:
-
Virtual appliances: preserve forensic information in accordance with your own incident guidelines, deploy a new virtual machine with a fixed version, rebuild the configuration, rotate credentials and all cryptographic materials installed on the appliance, and continue monitoring the system for anomalies. If recovery is not possible, Cisco recommends contacting Cisco TAC.
-
Physical appliances: contact Cisco TAC if compromise is suspected.
-
Clusters: Cluster members authenticate with each other using SSH key pairs. Private keys can be extracted from a compromised appliance, potentially enabling access to additional cluster members. Cisco recommends restoring every member of a cluster with at least one compromised appliance to a secure configuration.
-
Secure Email Cloud: Contacted customers should rotate credentials and cryptographic materials.
Assessment
Affected organizations are those operating Cisco Secure Email Gateway as a mail gateway in front of their mail server, regardless of its configuration. Because the attack occurs through incoming mail flow and Cisco considers all configurations affected, every installation that accepts emails from outside is vulnerable. The gateway processes all messages for an organization and holds credentials and key material; command execution as root gives an attacker access to both.
AsyncOS has been targeted before: according to BleepingComputer, the AsyncOS vulnerability CVE-2025-20393 had been exploited since November 2025 and was patched in January. In Europe, Germany’s BSI (cybersecurity warning of September 14, 2026) and CERT-FR (advisory of September 15, 2026), among others, warned about CVE-2026-76461.
Comments
Comments are loaded from GitHub / Giscus.