ZeroHour
Security Affairspublished ()ingested Pierluigi Paganini
Part of a story covered by 15 sources: “Cisco Warns of Actively Exploited Zero-Day CVE-2026-76461 in Secure Email Gateway: Crafted Email Yields Unauthenticated Root Command Execution” — merged summary and timeline →

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 85CVE-2026-76461
AI summary · glm-5.3

CISA added actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) to KEV; federal agencies must patch by September 17, 2026.

CISA added CVE-2026-76461 (CVSS 9.8), a critical zero-day in Cisco AsyncOS for Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog. The flaw stems from insufficient validation in email parsing, letting an unauthenticated remote attacker send a crafted email with malicious SQL statements to achieve arbitrary command execution with root privileges. Cisco confirmed active exploitation in the wild, notes no workarounds exist, and recommends checking mail_logs for suspicious SQL statements like 'COPY.*TO PROGRAM' on every cluster device. Under BOD 22-01, FCEB agencies must remediate by September 17, 2026.

  • CVE-2026-76461 is CVSS 9.8 unauthenticated remote root command execution
  • Exploited via crafted emails containing malicious SQL statements in parsing logic
  • Cisco confirmed active exploitation; no workarounds available
  • Affects physical and virtual Secure Email Gateways regardless of configuration
  • FCEB agencies must patch by September 17, 2026 under BOD 22-01

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-76461
Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway

Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent.

Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts.

9.82% KEV PoC ×2
  • Cisco Secure Email Gateway (Cisco AsyncOS Software)
large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances)
Full article456 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 15, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog.

Cisco disclosed a critical zero-day CVE-2026-76461 this week; the flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL statements, triggering arbitrary command execution on the underlying system with root privileges. Cisco confirmed the vulnerability is already being exploited in the wild.

“A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.” reads the report published by the networking giant.

“This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.”

According to the advisory, the vulnerability affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration. The company states that there are no workarounds that address this issue.

Recently, the company’s PSIRT became aware of active exploitation of this vulnerability.

Check Secure Email Gateway logs for suspicious SQL statements to detect possible exploitation. If the device is part of a cluster, check every device. Cisco says customers using Secure Email Cloud may not be able to check these indicators themselves, but those with detected malicious activity were contacted directly.

“To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device.” states the advisory. “The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs:

cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]

The presence of any entry in the output may indicate malicious activity.”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaw by September 17, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/199156/security/u-s-cisa-adds-cisco-secure-email-gateway-flaw-to-its-known-exploited-vulnerabilities-catalog.html