TL;DR
Cisco confirmed active attacks on a critical Cisco Secure Email Gateway vulnerability. Tracked as CVE-2026-76461, it scores a CVSS 9.8. An unauthenticated attacker can send a crafted email and run commands as root.
- CVE: CVE-2026-76461
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Cisco Secure Email
- Affected: 14.0.0-698, 13.5.1-277, 13.0.0-392, 14.2.0-620, 13.0.5-007, 13.5.4-038 (+17 more)
- Impact: Cisco Secure Email Gateway SQL Injection Vulnerability
- Status: Exploited in the wild
- Action: See vendor advisory
Track every Cisco CVE the moment it's exploited.
Get free email alertsWhy this Cisco Secure Email Gateway vulnerability matters
Email gateways sit at the edge of corporate networks. They inspect every inbound message. A root-level flaw there hands attackers deep control.
Cisco PSIRT confirms the danger is live. In its advisory, Cisco says it “became aware of active exploitation of this vulnerability” in September 2026. There are no workarounds, which makes patching the only fix.
Also, CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
How the attack works
The flaw is a SQL injection bug in the email parsing logic of Cisco AsyncOS. According to Cisco, “insufficient validation in the email parsing logic” causes it. An attacker sends a crafted email containing malicious SQL statements.
The device then runs those statements. As Cisco explains, a successful exploit leads to “command execution with root privileges on the underlying operating system.” No authentication and no user interaction are required.
Check for signs of compromise
Cisco warns that root access lets attackers hide their tracks. Administrators should review mail_logs for suspicious SQL statements. Because logs on the device may be tampered with, cross-check external network and firewall logs too.
Affected versions
The bug affects Cisco Secure Email Gateway, both physical and virtual, regardless of configuration. It does not affect Secure Web Appliance or Secure Email and Web Manager. Cisco fixed it in releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780.
Patch and mitigation steps
Upgrade to a fixed AsyncOS release right away. Cisco recommends migrating to 16.5.0-780. Since no workaround exists, do not delay the update. Finally, restrict appliance access to trusted hosts and monitor logs closely.
| Cisco AsyncOS for Cisco Secure Email Gateway Software Release | First Fixed Release |
|---|---|
| 15.5 and earlier | 15.5.5-014 |
| 16.0 | 16.0.4-302 |
| 16.5 | 16.5.0-780 |
To upgrade a device by using the web-based management interface, do the following:
- Choose System Administration > System Upgrade.
- Click Upgrade Options.
- Click Download and Install.
- Choose a release to upgrade to.
- In the Upgrade Preparation area, choose the appropriate options.
- Click Proceed to begin the upgrade. A progress bar displays the status of the upgrade.
After the upgrade is complete, the device reboots.
To upgrade a device by using the CLI, do the following:
- Run upgrade.
- Enter DOWNLOADINSTALL.
- Choose a release to upgrade to.
- Choose the appropriate options throughout the upgrade process.
After the upgrade is complete, the device reboots.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!