Critical Cisco Secure Email Gateway zero-day gives attackers root access
Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 lets crafted emails trigger SQL injection and root command execution; CISA added it to KEV.
Cisco released emergency patches for CVE-2026-76461, a critical SQL injection in Secure Email Gateway (physical and virtual) caused by insufficient validation in email parsing. Sending a crafted email with malicious SQL statements can yield arbitrary command execution with root privileges. Cisco was aware of active exploitation before the fixes, and CISA added the flaw to its KEV catalog; patched AsyncOS releases are 15.5.5-0141, 16.0.4-3021, and 16.5.0-780. Because successful exploits grant root, Cisco warns logs may be tampered with and advises checking external firewall/network logs and rebuilding virtual appliances with rotated credentials.
- Zero-day exploited in the wild in Cisco Secure Email Gateway; added to CISA KEV
- Crafted email triggers SQL injection leading to root-level command execution
- Fixed in AsyncOS 15.5.5-0141, 16.0.4-3021, and 16.5.0-780
- Second Secure Email Gateway flaw ever added to KEV after CVE-2025-20393
- Root access lets attackers alter device logs to hide compromise
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20393 | Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined. Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown. | 10.0 | 30% | KEV |
| largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished) | |
| CVE-2026-76461 | Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent. Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts. | 9.8 | 2% | KEV PoC ×2 |
| large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances) |
Full article448 words · extracted from csoonline.com · click to collapse
Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released.
Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this appliance’s main job, which means the attack vector is trivial.
“An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in its advisory. “A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.”
The flaw affects both the physical and virtual versions of the product and was fixed in the AsyncOS firmware releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 released Monday. The Cisco product security team became aware of active exploitation of this vulnerability earlier this month, and the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog.
Indicators of compromise might be missing
Because the vulnerability has been exploited as a zero-day, just upgrading to the patched firmware version is not enough. Organizations should also try to determine whether their own appliances have been compromised.
One way is to review the mail_logs for suspicious SQL statements. However, because successful exploitation gives attackers root access on the device, they could use this access to alter the logs and hide their tracks. Cisco advises organizations to also check any network and firewall logs outside the device for any signs of suspicious activity, such as file uploads or downloads between the device and external IP addresses.
If exploitation is suspected on physical devices, Cisco recommends contacting the Cisco Technical Assistance Center. For virtual devices, customers are advised to save all forensic information then deploy a new instance with rebuilt configuration and rotated credentials.
Devices that are enrolled in Cisco Secure Email Cloud have already been reviewed by Cisco and the owners of the devices that showed potential signs of compromise were contacted. The company’s advisory also includes general recommendations for device security hardening.
“A root-level, unauthenticated RCE in an email gateway is about as good a foothold as an attacker gets,” Josh Picolet, vice president of detection and analysis at security firm Team Cymru, tells CSO. “This is only the second Secure Email Gateway flaw ever added to CISA’s KEV catalog, after CVE-2025-20393, and that repetition fits actors who treat edge appliances as durable, reusable access rather than one-off targets.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4222391/critical-cisco-secure-email-gateway-zero-day-gives-attackers-root-access.html