Cisco security advisory (AV26-921)
Canadian Cyber Centre warns actively exploited Cisco Secure Email Gateway SQL injection CVE-2026-76461 was added to CISA's KEV database.
The Canadian Centre for Cyber Security advisory AV26-921 (September 14, 2026) covers a SQL injection vulnerability in Cisco Secure Email Gateway (AsyncOS) and Secure Email and Web Manager. Affected versions include AsyncOS/Secure Email Gateway prior to 15.5.5-014, 16.0.4-302, and 16.5.0-780, and Secure Email and Web Manager prior to 15.5.5-006 and 16.5.0-429. Cisco stated CVE-2026-76461 is being actively exploited, and CISA added it to the Known Exploited Vulnerabilities database the same day. Users and administrators are urged to apply updates as they become available.
- CVE-2026-76461 affects Cisco Secure Email Gateway and Secure Email and Web Manager.
- Cisco confirmed active exploitation of the SQL injection flaw.
- CISA added CVE-2026-76461 to the KEV database on September 14, 2026.
- Administrators should patch affected AsyncOS versions promptly.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76461 | Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent. Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts. | 9.8 | 2% | KEV PoC ×2 |
| large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances) |
Full article140 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-921
Date: September 14, 2026
As of September 14, 2026, Cisco is affected by vulnerabilities in the following products:
- Cisco AsyncOS for Cisco Secure Email Gateway
- Prior to 15.5.5-014
- Prior to 16.0.4-302
- Prior to 16.5.0-780
- Cisco Secure Email Gateway
- Prior to 15.5.5-014
- Prior to 16.5.0-780
- Cisco Secure Email and Web Manager
- Prior to 15.5.5-006
- Prior to 16.5.0-429
On September 14, 2026, Cisco stated that CVE-2026-76461 is being actively exploited.
On September 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-921