ZeroHour
Help Net Securitypublished ()ingested Zeljka Zorz
Part of a story covered by 15 sources: “Cisco Warns of Actively Exploited Zero-Day CVE-2026-76461 in Secure Email Gateway: Crafted Email Yields Unauthenticated Root Command Execution” — merged summary and timeline →

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

criticalExploit / PoC exploited in the wildimportance 85CVE-2026-76461CVE-2025-20393
AI summary · glm-5.3

Actively exploited zero-day SQL injection (CVE-2026-76461) in Cisco Secure Email Gateway allows unauthenticated root command execution; CISA ordered federal remediation by September 17.

Cisco confirmed attackers are exploiting zero-day CVE-2026-76461, an unauthenticated SQL injection in the email parsing logic of AsyncOS on Secure Email Gateway appliances (versions 16.5, 16.0, 15.5 and earlier) and Secure Email Cloud. Successful exploitation yields arbitrary SQL execution and root-level command execution on the underlying OS without user interaction. Cisco became aware of active exploitation in September 2025, has directly contacted affected cloud customers, and released fixed releases 15.5.5-014, 16.0.4-302, and 16.5.0-780. CISA added the flaw to its Known Exploited Vulnerabilities catalog and required federal civilian agencies to patch by September 17 and hunt for compromise.

  • Unauthenticated SQL injection via crafted email gives attackers root command execution on affected appliances.
  • Affects AsyncOS 15.5/16.0/16.5 and earlier on physical, virtual, and cloud Secure Email Gateways.
  • CISA added CVE-2026-76461 to KEV with a September 17 federal remediation deadline.
  • Fix releases 15.5.5-014 and 16.5.0-780 also patch several additional critical vulnerabilities.
  • Root-level attackers may purge logs and hide indicators, so external network and firewall logs should be reviewed.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20393
Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands

CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined.

Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown.

10.030% KEV
  • Cisco Secure Email Gateway / Secure Email
  • Cisco AsyncOS Software
  • Cisco Web Manager appliance
largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished)
CVE-2026-76461
Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway

Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent.

Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts.

9.82% KEV PoC ×2
  • Cisco Secure Email Gateway (Cisco AsyncOS Software)
large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances)
Full article539 words · extracted from helpnetsecurity.com · click to collapse

Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday.

CVE-2026-76461 Cisco email gateway zero-day

The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared indicators of compromise that organizations can look for to check whether they’ve been hit.

About CVE-2026-76461

The vulnerability affects versions 16.5, 16.0, and 15.5 and earlier of Cisco AsyncOS Software, running on on-premises physical and virtual Secure Email Gateway appliances.

It also affected the cloud-delivered version of Cisco’s Secure Email Gateway – Cisco Secure Email Cloud – and Cisco said it “has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected.”

The flaw is due to insufficient validation in the email parsing logic, and can be triggered by an unauthenticated attacker sending a crafted email message that contains malicious SQL statements through an affected device.

Successful exploitation does not hinge on user interaction.

What to look for?

“A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system,” Cisco explained.

The vendor advised organizations using Cisco Secure Email Gateway check the devices’ mail_logs for suspicious SQL statements.

“The presence of any entry in the output may indicate malicious activity. If the device is part of a cluster, review the logs of each cluster device,” Cisco added.

But, it also noted that since threat actors may obtain command execution with root privileges, they may use this access to delete/hide evidence of exploitation and indicators of compromise.

(Late last year, for example, a suspected Chinese-nexus threat group used log-purging tools after planting backdoors following zero-day exploitation of CVE-2025-20393.)

“Cisco strongly recommends that administrators cross-check the network logs and the firewall logs outside of the impacted device to identify any potential suspicious activity, including but not limited to unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses,” the company noted.

What to do?

Cisco has already upgraded all Cisco Secure Email Cloud devices to Release 16.5.0-780.

To plug CVE-2026-76461, Cisco recommends enterprise admins to upgrade their devices to a fixed release: 15.5.5-014, 16.0.4-302, or 16.5.0-780 (the latter is preferred). 15.5.5-014 and 16.5.0-780 are also software hardening releases, and carry fixes for a slew of additional critical vulnerabilities that were discovered by the vendor.

After the upgrade, security teams should search for the presence of indicators of compromise in various logs. If found, they should either:

  • Contact the Cisco Technical Assistance Center (TAC) for support (if they are running physical devices)
  • Record forensics information, deploy a new virtual machine running one of the fixed software releases, rebuild the product configuration, renew credentials and any cryptographic materials that are installed on the appliance, and continue to monitor the system for anomalous behavior.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on Monday, and ordered US federal civilian agencies to remediate the flaw by Thursday (September 17) and check for evidence of compromise.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/15/cve-2026-76461-cisco-email-gateway-zero-day-exploited/