ZeroHour
Cyber Security Newspublished ()ingested Abinaya
Part of a story covered by 15 sources: “Cisco Warns of Actively Exploited Zero-Day CVE-2026-76461 in Secure Email Gateway: Crafted Email Yields Unauthenticated Root Command Execution” — merged summary and timeline →

CISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks

criticalExploit / PoC exploited in the wildimportance 92CVE-2026-76461
AI summary · glm-5.3

CISA added actively exploited Cisco Secure Email Gateway SQL injection flaw CVE-2026-76461 to its KEV catalog, enabling unauthenticated root command execution.

CVE-2026-76461 is an unauthenticated SQL injection (CWE-89) in Cisco AsyncOS for Cisco Secure Email Gateway appliances, allowing remote attackers to execute arbitrary OS commands with root privileges. CISA added the flaw to the KEV catalog on September 14, 2026, requiring federal civilian agencies to apply vendor mitigations by September 17, 2026, and forensic triage under BOD 26-04. A compromised gateway could let attackers alter email security policies, access stored messages, disable logging, and pivot into enterprise networks.

  • CVE-2026-76461: unauthenticated SQL injection in Cisco AsyncOS enables root command execution
  • CISA added flaw to KEV September 14, 2026; mitigation deadline September 17
  • Forensic triage required under Binding Operational Directive 26-04
  • Unpatched internet-facing appliances should be treated as potentially compromised

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76461
Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway

Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent.

Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts.

9.82% KEV PoC ×2
  • Cisco Secure Email Gateway (Cisco AsyncOS Software)
large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances)
Full article447 words · extracted from cybersecuritynews.com · click to collapse

CISA has added a critical Cisco Secure Email Gateway vulnerability to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw in real-world attacks.

The issue, tracked as CVE-2026-76461, affects Cisco AsyncOS software used by Cisco Secure Email Gateway appliances. CVE-2026-76461 is an SQL injection vulnerability, categorized under CWE-89.

It could allow an unauthenticated remote attacker to send specially crafted requests to a vulnerable Cisco Secure Email Gateway device and execute arbitrary commands on the underlying operating system.

Successful exploitation may provide root-level privileges, giving an attacker full control of the affected appliance. Cisco Secure Email Gateway is commonly deployed at the edge of enterprise networks to inspect email traffic and block malicious messages, spam, phishing attempts, and malware.

Compromising such a system could create serious security risks because the appliance processes large volumes of inbound and outbound email, including messages containing sensitive business information.

An attacker with root access could potentially alter email security policies, access stored message data, create persistence mechanisms, turn off security logging, or use the compromised gateway as an entry point into the wider network.

Cisco Secure Email Gateway 0-Day Vulnerability Exploited

Security teams should also investigate whether the appliance has communicated with unfamiliar external infrastructure or shown unexpected administrative activity.

CISA added the vulnerability to the KEV catalog on September 14, 2026, and directed affected federal civilian executive branch agencies to apply vendor-provided mitigations by September 17, 2026.

The agency also marked the issue as requiring forensic triage under Binding Operational Directive 26-04, reflecting the elevated risk associated with confirmed exploitation.

The listing does not confirm whether the vulnerability has been used in ransomware operations. However, vulnerabilities that enable unauthenticated remote command execution with root privileges are highly valuable to threat actors, particularly when the affected product is internet-facing.

Organizations using Cisco Secure Email Gateway should identify all exposed AsyncOS instances, confirm their software versions, and apply Cisco’s recommended mitigation measures as soon as possible.

Where mitigations are unavailable, CISA advises organizations to follow applicable BOD 26-04 guidance for cloud services or discontinue use of the affected product. Security teams should prioritize incident-response checks alongside remediation.

Relevant triage actions include reviewing appliance logs for suspicious requests, checking for unauthorized configuration changes, examining privileged account activity, and looking for unexpected command execution or outbound network connections.

Because the flaw can be exploited remotely without authentication, organizations should treat any unpatched internet-accessible device as potentially compromised.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/cisco-secure-email-gateway-0-day-vulnerability-exploited/