CVE-2026-76461: Critical Cisco Secure Email Gateway SQL Injection Flaw Under Active Exploitation
Summary
Cisco has released security updates for a critical SQL injection vulnerability affecting Cisco Secure Email Gateway. The flaw, identified as CVE-2026-76461, carries a CVSS score of 9.8 and can be exploited remotely without authentication or user interaction.
The vulnerability exists because Cisco AsyncOS does not sufficiently validate data processed by its email-parsing logic. A crafted email containing malicious SQL statements can trigger arbitrary SQL execution and subsequently allow operating-system commands to be executed with root privileges.
Cisco confirmed that the vulnerability affects both physical and virtual Cisco Secure Email Gateway appliances regardless of device configuration. Cisco PSIRT became aware of active exploitation in September 2026.
Vulnerability Details
| CVE ID | CVSS Score | EPSS Score | Type |
|---|---|---|---|
| CVE-2026-76461 | 9.8 | 2.16% | SQL Injection leading to Root Command Execution |
Technical Information
CVE-2026-76461 — SQL Injection in Email Parsing Leading to Root Command Execution
CVE-2026-76461 is caused by insufficient validation in the email-parsing functionality of Cisco AsyncOS Software running on Cisco Secure Email Gateway.
The vulnerable logic processes attacker-controlled data contained in email messages passing through the gateway. An unauthenticated remote attacker can exploit the flaw by sending a specially crafted email containing malicious SQL statements through an affected appliance.
Because the malicious input reaches the vulnerable component through the normal email-processing workflow, an attacker does not require an authenticated account, administrative access, or user interaction.
Successful exploitation allows the attacker to execute arbitrary SQL statements. Cisco states that this can subsequently lead to arbitrary command execution with root privileges on the underlying operating system.
The vulnerability has the following CVSS v3.1 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This reflects remote network exploitation, low attack complexity, no authentication requirement, no user interaction, and high impact to confidentiality, integrity, and availability.
Affected Products
CVE-2026-76461
The vulnerability affects:
- • Cisco Secure Email Gateway physical appliances
- • Cisco Secure Email Gateway virtual appliances
Cisco states that Secure Email Gateway appliances are vulnerable regardless of device configuration.
Cisco has confirmed that the following products are not affected:
- • Cisco Secure Email and Web Manager
- • Cisco Secure Web Appliance
Affected and Fixed Versions
Cisco has released fixed versions of AsyncOS Software for affected Cisco Secure Email Gateway appliances.
| Cisco AsyncOS Release | First Fixed Release |
|---|---|
| 15.5 and earlier | 15.5.5-014 |
| 16.0 | 16.0.4-302 |
| 16.5 | 16.5.0-780 |
Cisco strongly recommends that customers running the 15.5 and 16.0 release trains migrate to AsyncOS Release 16.5.0-780.
Cisco has also confirmed that all Cisco Secure Email Cloud devices have already been upgraded to Release 16.5.0-780.
Impact
Successful exploitation of CVE-2026-76461 allows an unauthenticated remote attacker to execute attacker-controlled SQL statements through the Secure Email Gateway email-processing path and ultimately execute operating-system commands with root privileges.
Root-level command execution provides the attacker with the highest privilege level on the underlying appliance. Cisco specifically warns that attackers with this level of access may be able to remove or hide evidence of exploitation and indicators of compromise stored on the affected device.
Because Cisco Secure Email Gateway is positioned directly in the email-processing path, compromise of the appliance also places a critical security control itself under attacker control.
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Tactic |
|---|---|---|
| T1190 | Exploit Public-Facing Application | Initial Access |
Mitigation and Recommendations
Cisco has confirmed that there are no workarounds for CVE-2026-76461. Organizations using affected Cisco Secure Email Gateway appliances should prioritize the following actions:
- • Upgrade Cisco AsyncOS: Upgrade 15.5 and earlier to at least 15.5.5-014, 16.0 to at least 16.0.4-302, and 16.5 to at least 16.5.0-780. Cisco recommends migrating applicable deployments to Release 16.5.0-780.
- • Review external telemetry: Correlate appliance activity with externally stored firewall and network logs because an attacker with root privileges may be able to remove or conceal evidence stored locally on the compromised gateway.
- • Investigate suspicious network activity: Look for unexpected outbound connections, uploads from the Secure Email Gateway to external IP addresses, and downloads from known or suspected malicious IP addresses.
- • Handle suspected physical appliance compromise: Contact Cisco Technical Assistance Center (TAC) for investigation and recovery assistance if exploitation is suspected on an on-premises physical appliance.
- • Rebuild compromised virtual appliances: Preserve forensic evidence, deploy a new virtual machine running a fixed AsyncOS release, rebuild the configuration, and renew credentials and cryptographic material associated with the appliance.
- • Restrict appliance exposure: Prevent unnecessary internet access and restrict required access and management traffic to known and trusted hosts.
Instantly Fix Risks with Saner Patch Management
Saner Patch Management is a continuous, automated, and integrated patch management solution that helps organizations rapidly remediate security risks across Windows, Linux, macOS, and a broad range of third-party applications.
The platform supports automated deployment workflows, patch testing, compliance reporting, and rollback capabilities to help reduce operational risk while keeping critical software updates moving quickly across enterprise environments.
Experience the fastest and most accurate patching software here .




