6 October 2026 7 min read

CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Is Being Exploited—Update and Check for Compromise

A specially crafted email is all it takes: via an SQL injection in AsyncOS, attackers can execute commands with root privileges on Cisco Secure Email Gateway (CVE-2026-76461, CVSS 9.8). The vulnerability is being exploited, and no workaround is available. Updating to a fixed version and checking for compromise are required.

On September 14, 2026, Cisco published advisory cisco-sa-esa-inj-2bLVGmhX regarding a critical vulnerability in AsyncOS for Cisco Secure Email Gateway. A specially crafted email processed by the gateway contains SQL statements that are executed due to insufficient validation in the processing logic; this results in arbitrary command execution with root privileges on the underlying operating system. No authentication is required. The vulnerability is identified as CVE-2026-76461 and has a CVSS score of 9.8. Cisco learned of active exploitation in September 2026; the U.S. agency CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on September 14, 2026. Updates are available, and Cisco states that no workaround exists.

Support with updating and checking

If you need help securing, checking for compromise, or updating Cisco Secure Email Gateway, please use the contact form on adeptio.ch. I can also get back to you at short notice.

Key points at a glance

FeatureDetails
Advisorycisco-sa-esa-inj-2bLVGmhX, published September 14, 2026, revision 1.1 dated September 17, 2026
CVECVE-2026-76461 (Cisco Bug ID CSCwu56234)
SeverityCVSS 3.1: 9.8 (critical), AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability typeSQL injection (CWE-89) in AsyncOS email processing, with command execution as root
Prerequisiteno authentication; a specially crafted email passing through the gateway
AffectedCisco Secure Email Gateway, physical and virtual, regardless of configuration
Not affectedSecure Email and Web Manager, Secure Web Appliance
Fixed versions15.5.5-014, 16.0.4-302, 16.5.0-780
Exploitationconfirmed by Cisco (known since September 2026); CISA KEV since September 14, 2026
CISA deadline for U.S. federal agenciesSeptember 17, 2026
Workaroundnone

Affected versions and updates

Version branchAffectedFixed in
AsyncOS 15.5 and earlierall versions before 15.5.5-01415.5.5-014
AsyncOS 16.0all versions before 16.0.4-30216.0.4-302
AsyncOS 16.5all versions before 16.5.0-78016.5.0-780

Cisco explicitly recommends migrating systems running a version earlier than 16.5 to 16.5.0-780. According to Cisco, it has already updated all devices for Cisco Secure Email Cloud customers to 16.5.0-780.

The CLI displays the installed version with:

version

What is known about the exploitation

Cisco states in the advisory that Cisco PSIRT learned of active exploitation in September 2026. The vulnerability was discovered while handling a support case in Cisco TAC. Secure Email Cloud customers whose devices Cisco found to have malicious activity were contacted directly.

Neither Cisco nor CISA provides details on the attacker, the number of affected organizations, or the precise start of the attacks (as of October 6, 2026). CISA lists whether the vulnerability is used in ransomware campaigns as unknown in the KEV entry. The three-day deadline between inclusion in the KEV Catalog and remediation is short; in addition to the vendor’s measures, CISA explicitly requires U.S. federal agencies to conduct forensic triage.

The attack path is the normal mail flow: the specially crafted message merely needs to pass through the gateway. Blocking the management interface from the internet therefore does not prevent exploitation.

Immediate measures

  1. Determine the version with version in the CLI and compare it with the table above. For clusters, this applies to every member.

  2. Check for compromise before updating (see the next section) and preserve logs. If compromise is suspected, follow Cisco’s recommendations for rebuilding rather than merely updating.

  3. Install the update: If there is no indication of exploitation, Cisco recommends updating to a fixed version and migrating systems earlier than 16.5 to 16.5.0-780.

  4. Reduce exposure: In the advisory, Cisco lists general hardening measures, including restricting internet access, placing mail and management functions on separate interfaces, operating the appliance behind a firewall, disabling HTTP for the management interface, and disabling unnecessary services. These measures reduce the attack surface but do not close the vulnerability in the mail flow.

  5. Monitor the advisory: Cisco updates the advisory when new information becomes available, most recently on September 17, 2026, with the note about clusters.

Checking for compromise

Cisco recommends checking the mail logs (default name mail_logs) for suspicious SQL statements and provides the following non-exhaustive example:

grep -i "COPY.*TO PROGRAM" mail_logs
Options explained
OptionEffect
grepsearches a log subscription in the AsyncOS CLI
-iignores case
"COPY.*TO PROGRAM"search pattern according to the advisory: lines containing COPY, followed by TO PROGRAM
mail_logsname of the log subscription for text mail logs (IronPort Text Mail Logs); adjust if named differently

If the device is part of a cluster, Cisco says the logs of every cluster member must be checked. An empty search result does not prove that a system is clean: an attacker with root privileges can remove traces from the device. Cisco therefore recommends correlating network and firewall logs outside the device, especially for unexpected uploads from the gateway to external IP addresses and downloads from malicious IP addresses. Cisco does not provide specific IP addresses, file names, or hash values in the advisory.

An update does not remove changes already made by an attacker. In the event of suspected compromise, Cisco recommends the following depending on the deployment:

  1. Virtual appliances: preserve forensic information in accordance with your own incident guidelines, deploy a new virtual machine with a fixed version, rebuild the configuration, rotate credentials and all cryptographic materials installed on the appliance, and continue monitoring the system for anomalies. If recovery is not possible, Cisco recommends contacting Cisco TAC.

  2. Physical appliances: contact Cisco TAC if compromise is suspected.

  3. Clusters: Cluster members authenticate with each other using SSH key pairs. Private keys can be extracted from a compromised appliance, potentially enabling access to additional cluster members. Cisco recommends restoring every member of a cluster with at least one compromised appliance to a secure configuration.

  4. Secure Email Cloud: Contacted customers should rotate credentials and cryptographic materials.

Assessment

Affected organizations are those operating Cisco Secure Email Gateway as a mail gateway in front of their mail server, regardless of its configuration. Because the attack occurs through incoming mail flow and Cisco considers all configurations affected, every installation that accepts emails from outside is vulnerable. The gateway processes all messages for an organization and holds credentials and key material; command execution as root gives an attacker access to both.

AsyncOS has been targeted before: according to BleepingComputer, the AsyncOS vulnerability CVE-2025-20393 had been exploited since November 2025 and was patched in January. In Europe, Germany’s BSI (cybersecurity warning of September 14, 2026) and CERT-FR (advisory of September 15, 2026), among others, warned about CVE-2026-76461.

Sources

  1. Cisco: Cisco Secure Email Gateway SQL Injection Vulnerability (cisco-sa-esa-inj-2bLVGmhX)

    Advisory with description, CVSS vector, fixed versions, indicators, and recommendations for physical, virtual, clustered, and cloud devices.

    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
  2. NVD: CVE-2026-76461

    CVE entry with CVSS, CWE-89, affected version ranges, and KEV data.

    https://nvd.nist.gov/vuln/detail/CVE-2026-76461
  3. CISA: Known Exploited Vulnerabilities Catalog, CVE-2026-76461

    KEV entry with inclusion date, deadline, required action, and ransomware status.

    https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461
  4. CISA: CISA Adds One Known Exploited Vulnerability to Catalog
  5. BSI: Cisco Secure Email Gateway, active exploitation of a zero-day vulnerability
  6. CERT-FR: Multiple vulnerabilities in Cisco products (CERTFR-2026-AVI-1175)

    Advisory of September 15, 2026, noting active exploitation and the search pattern for mail logs.

    https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1175/
  7. BleepingComputer: Cisco patches Secure Email Gateway zero-day exploited in attacks

    Report of September 15, 2026, with the deadline for U.S. federal agencies and a reference to CVE-2025-20393.

    https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/
  8. The Hacker News: Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
  9. Truesec: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

    Assessment of September 17, 2026, recommending that mail and cluster logs be checked.

    https://www.truesec.com/hub/blog/critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild
  10. Cisco: CLI Reference Guide for AsyncOS 15.5.3 for Cisco Secure Email Gateway

Comments

Comments are loaded from GitHub / Giscus.