Cisco Warns of Actively Exploited Zero-Day CVE-2026-76461 in Secure Email Gateway: Crafted Email Yields Unauthenticated Root Command Execution
CVSS 9.8 unauthenticated SQL-injection zero-day CVE-2026-76461 in Cisco Secure Email Gateway AsyncOS is being exploited in the wild, letting a single crafted email deliver root command execution; CISA added it to the KEV catalog with a September 17, 2026…
Cisco PSIRT disclosed CVE-2026-76461, a critical CVSS 9.8 unauthenticated SQL injection (CWE-89) in AsyncOS for Cisco Secure Email Gateway caused by insufficient validation in email-parsing logic. A remote, unauthenticated attacker can execute arbitrary SQL statements — and thereby arbitrary OS commands with root privileges — simply by sending a crafted email through a vulnerable gateway; no authentication or user interaction is required. The flaw affects physical appliances, virtual deployments, and Cisco Secure Email Cloud regardless of configuration, and no workarounds exist. Cisco became aware of active exploitation in September 2026, and exploitation occurred before disclosure; some Secure Email Cloud customers showed indicators of compromise, with Cisco deploying server-side remediations (The Register reports all cloud devices were upgraded to AsyncOS 16.5.0-780) and directly contacting affected cloud customers, while on-premises admins must patch themselves. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14, 2026 — the disclosure day — and federal civilian agencies must apply vendor mitigations by September 17, 2026 (the governing directive is reported inconsistently: Cyber Security News cites BOD 26-04 with mandatory forensic triage, while Security Affairs cites BOD 22-01); unpatched internet-facing appliances should be treated as potentially compromised, and Shadowserver counted more than 400 internet-exposed appliances. CSO Online notes this is the second Secure Email Gateway flaw ever added to KEV, after CVE-2025-20393. A compromised gateway could let attackers alter email security policies, access stored messages, silently monitor email, disable logging, and pivot into enterprise networks (Rapid7 and VulnCheck warn of silent monitoring and internal pivoting); because root-level attackers may purge or tamper with logs, Cisco advises reviewing external firewall/network logs, taking forensic snapshots, rebuilding appliances, and rotating credentials. Detection guidance: grep mail_logs on each clustered device for suspicious SQL statements such as 'COPY.*TO PROGRAM'. Fixed releases are consistently reported as AsyncOS 16.5.0-780, but sources disagree on the branch versions: 16.0.4-3021 and 15.5.5-0141 (Cyber Security News, CSO Online) versus 16.0.4-302 and 15.5.5-014 (The Register, Rapid7, The Hacker News mixes both). Rapid7 reports no public PoC and no threat-actor attribution. The Hacker News separately notes…
- CVE-2026-76461 is a CVSS 9.8 unauthenticated SQL injection (CWE-89) in Cisco AsyncOS for Secure Email Gateway caused by insufficient email-parsing validation.
- A crafted email containing malicious SQL statements gives a remote, unauthenticated attacker arbitrary command execution with root privileges; no workarounds exist.
- Actively exploited in the wild before disclosure; Cisco PSIRT became aware of exploitation in September 2026.
- CISA added the flaw to its KEV catalog on September 14, 2026, requiring FCEB agencies to remediate by September 17, 2026 — sources conflict on the directive (BOD 26-04 per Cyber Security News vs. BOD 22-01 per Security Affairs).
- Fixed in AsyncOS 16.5.0-780 plus branch releases; sources disagree on exact build numbers: 16.0.4-3021/15.5.5-0141 vs. 16.0.4-302/15.5.5-014.
- Affects physical appliances, virtual deployments, and Cisco Secure Email Cloud regardless of configuration; Cisco applied server-side cloud fixes (all cloud devices reportedly upgraded to 16.5.0-780) and contacted affected cloud customers…
- Shadowserver counted more than 400 internet-exposed Cisco Secure Email Gateway appliances.
- Detection: grep mail_logs on each clustered device for suspicious SQL statements such as 'COPY.*TO PROGRAM'; root-level attackers may tamper with logs, so external firewall/network logs, forensic snapshots, rebuilds, and credential…
Coverage timelineoldest first · each row is one article
- · 1d agoCISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories· 75
CISA added CVE-2026-76461, an actively exploited SQL injection in Cisco Secure Email Gateway, to the KEV catalog.
- · 1d agoCisco security advisory (AV26-921)
Canadian Centre for Cyber Security· 75
Canadian Cyber Centre warns actively exploited Cisco Secure Email Gateway SQL injection CVE-2026-76461 was added to CISA's KEV database.
- · 17h agoHackers Exploit Critical Cisco Secure Email Gateway Vulnerability in the Wild to Run Malicious Code
Cyber Security News· 88
Cisco warns attackers actively exploit zero-day CVE-2026-76461 in Secure Email Gateway, gaining unauthenticated root command execution via crafted emails.
- · 16h agoHackers Exploit Critical Cisco Secure Email Gateway Flaw to Execute Commands as Root
GBHackers· 78
Cisco patched critical unauthenticated SQL injection CVE-2026-76461 (CVSS 9.8) in Secure Email Gateway enabling root command execution, with malicious activity already detected.
- · 16h ago
- · 15h agoCisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
The Hacker News· 92
Cisco warns CVE-2026-76461 in Secure Email Gateway AsyncOS is actively exploited, letting unauthenticated attackers run root commands via crafted emails.
- · 10h agoCisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Help Net Security· 85
Actively exploited zero-day SQL injection (CVE-2026-76461) in Cisco Secure Email Gateway allows unauthenticated root command execution; CISA ordered federal remediation by September 17.
- · 9h agoCVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
Rapid7 Blog· 92
Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) enables unauthenticated root command execution via crafted email; CISA added it to KEV.
- · 8h agoCisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-Day
Security Affairs· 93
Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) is actively exploited for root command execution; CISA added it to KEV.
- · 7h agoCisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)
Qualys ThreatPROTECT· 82
Cisco Secure Email Gateway flaw CVE-2026-76461 enables root command execution via crafted email SQL injection and is actively exploited, added to CISA KEV.
- · 6h agoCISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks
Cyber Security News· 92
CISA added actively exploited Cisco Secure Email Gateway SQL injection flaw CVE-2026-76461 to its KEV catalog, enabling unauthenticated root command execution.
- · 5h agoCisco warns customers of actively exploited zero-day in email gateways
CyberScoop· 92
Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 allows unauthenticated root command execution; CISA added it to KEV.
- · 5h agoCisco email security boxes can be rooted by... an email
The Register · Security· 92
Attackers actively exploit critical Cisco Secure Email Gateway flaw CVE-2026-76461, turning a malicious email into unauthenticated root access.
- · 1h agoCritical Cisco Secure Email Gateway zero-day gives attackers root access
CSO Online· 92
Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 lets crafted emails trigger SQL injection and root command execution; CISA added it to KEV.
- · 36m agoU.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
Security Affairs· 85
CISA added actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 (CVSS 9.8) to KEV; federal agencies must patch by September 17, 2026.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20393 | Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined. Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown. | 10.0 | 30% | KEV |
| largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished) | |
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-20316 | Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile). Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29. | 5.3 | 11% | KEV ransomware |
| largeplausibly tens of thousands of FMC deployments worldwide (no published install base) | |
| CVE-2026-76461 | Unauthenticated SQL Injection to Root RCE in Cisco Secure Email Gateway Cisco AsyncOS Software for Cisco Secure Email Gateway contains a SQL injection flaw (CWE-89) in its email parsing logic, caused by insufficient validation of message content. An unauthenticated, remote attacker can trigger it simply by sending a crafted email containing malicious SQL statements through an affected gateway, with no user interaction required. Successful exploitation allows arbitrary SQL execution that escalates to arbitrary operating-system command execution with root privileges, fully compromising the appliance and all mail flowing through it. Any organization running an affected version of Cisco Secure Email Gateway is impacted, and because these appliances sit on the inbound mail path they are inherently reachable over the network. There is no known public proof-of-concept, the flaw is not on the CISA KEV list, and no in-the-wild exploitation has been reported to date, though the CVSS 9.8 rating makes patching urgent. Do: Upgrade to the fixed AsyncOS release listed in the corresponding Cisco PSIRT advisory as soon as possible, since the flaw is unauthenticated, requires no user interaction, and yields root. Until patched, apply any Cisco-documented workarounds and tightly restrict which hosts can submit mail to the gateway where operationally feasible. Review mail and system logs on these appliances for anomalies such as SQL errors in parsing, unexpected processes, or unexplained outbound connections that could indicate exploitation attempts. | 9.8 | 2% | KEV PoC ×2 |
| large≈ tens of thousands of gateway deployments (order of 10,000–50,000 appliances) |