XHack Logo
XHack
Products
Services
Compliance
Pricing
Resources
Company
Sign upLogin
XHack Logo
XHackOffensive Security

Certified offensive security team delivering penetration testing evidence written for your auditor.

OSCP+OSCPC-AI/MLPenCASA
support@xhack.io

24/7 SOC Operations

XHack Status
Under attack? Get help now
Services
  • VAPT Services
  • Red Teaming
  • SOC Services
  • Threat Intelligence
  • Incident Response
  • Managed Testing
Pricing
  • Platform Plans
  • Services Pricing
Compliance
  • SOC 2
  • PCI DSS
  • ISO 27001
  • GDPR
  • HIPAA
  • ISO 42001
  • AI Maturity Assessment
  • TX-RAMP
  • NBFC / SECP
  • All Frameworks
Products
  • Vulnerability Assessment
  • GitGuard
  • AI Probe
  • SOC Dashboard
  • AI Agent
  • Cloud Investigation
Comparison
  • XBOW vs XHack
  • Horizon3 vs XHack
  • Strix vs XHack
  • Pentera vs XHack
Resources
  • Platform Tour
  • All Features
  • Install the Agent
  • XHack AI
  • Documentation
  • Blog
  • Case Studies
  • Documents
  • FAQ
Company
  • About Us
  • Our Team
  • Certifications
  • Security and Trust
  • VAPT Explained
  • Contact

© 2026 XHack. All rights reserved.

Security & TrustVulnerability DisclosurePrivacy PolicyTerms of ServiceRefund Policy
Blog/News

CVE-2026-76461: The Critical Cisco Email Gateway Bug Triggered by One Email

XHack

XHack

Author

October 7, 2026

13 min read

CVE-2026-76461: The Critical Cisco Email Gateway Bug Triggered by One Email

Table of contents

19

Why a Bug in an Email Gateway Is Different

What CVE-2026-76461 Is, According to Cisco

How the Attack Works: What Cisco Says and What It Doesn’t

Who Is Affected and Which Builds Fix It

Fixing CVE-2026-76461

Hunting for CVE-2026-76461 Exploitation

What a Root-Level Compromise via CVE-2026-76461 Puts at Risk

A First-Hour Plan for CVE-2026-76461

A Pattern: Mail Security Appliances Keep Reaching KEV

How XHack Reads CVE-2026-76461

FAQ: CVE-2026-76461 Questions Answered

What is CVE-2026-76461?

Is CVE-2026-76461 being exploited?

Which versions does CVE-2026-76461 affect?

Is there a workaround for CVE-2026-76461?

How do I check for CVE-2026-76461 exploitation?

Does CVE-2026-76461 affect Secure Email Cloud?

Does CVE-2026-76461 affect Secure Email and Web Manager?

The Bottom Line

Read this in 30 seconds: CVE-2026-76461 is a CVSS 9.8 SQL injection in Cisco Secure Email Gateway that lets an unauthenticated attacker run commands as root, and Cisco says it is being exploited.

  • The attack arrives as ordinary mail. Cisco says an attacker sends a crafted email containing malicious SQL statements through an affected device. No login and no management access are involved.
  • Configuration doesn’t protect you. Cisco says the bug affects physical and virtual gateways “regardless of device configuration,” and there are no workarounds.
  • The only fix is an upgrade. Move to 15.5.5-014, 16.0.4-302 or 16.5.0-780. Cisco recommends 16.5.0-780 for anything earlier than 16.5.
  • Root access means the logs may lie. Cisco warns that evidence of exploitation may be removed or hidden, so check network and firewall logs outside the device too.
  • CISA flagged it for forensic triage. Added to KEV on September 14, due September 17, which was 20 days ago.

An email gateway exists to accept untrusted messages from strangers, so a bug in how it reads them is a bug in its whole purpose.

Cisco published advisory cisco-sa-esa-inj-2bLVGmhX for CVE-2026-76461 on September 14, 2026, rated Critical. CISA added it to the Known Exploited Vulnerabilities catalog the same day with a three-day deadline.

This article covers what Cisco confirms, what it leaves unsaid about how the bug works, who is affected, the fixed builds, and how to check a gateway that may already have been hit.

CVE-2026-76461 severity summary: Cisco Secure Email Gateway, CVSS 9.8, unauthenticated SQL injection through crafted email leading to root command execution, actively exploited, added to CISA KEV September 14 2026
CVE-2026-76461 at a glance: one crafted email, root on the gateway

Why a Bug in an Email Gateway Is Different

Most critical bugs live in something an attacker has to find and reach: a login page, a management port, an API. A secure email gateway sits in the mail path and reads every message that crosses it. The input to CVE-2026-76461 is the thing the product is built to process.

That has three consequences, and Cisco’s advisory supports each of them.

  • No special access is needed. Cisco describes the attacker as unauthenticated and remote, and says exploitation works by sending a crafted message through the device.
  • No configuration choice removes it. Cisco says the bug affects the gateway “regardless of device configuration.”
  • No workaround exists. Cisco says so directly, and says the fix is a software upgrade.

CVE-2026-76461 affects Cisco Secure Email Gateway, both physical and virtual, and Cisco’s Secure Email Cloud service includes gateway devices, so it is in scope too. Cisco lists Secure Email and Web Manager and Secure Web Appliance as not vulnerable.

What CVE-2026-76461 Is, According to Cisco

Cisco attributes the flaw to “insufficient validation in the email parsing logic.” A successful attack lets the attacker run arbitrary SQL statements, which leads to command execution with root privileges on the underlying operating system.

What we can confirm from primary sources:

  • Weakness: CWE-89, SQL injection.
  • Score: CVSS 3.1 base 9.8, vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The score comes from Cisco, not from NVD’s own analysts.
  • Exploited: yes. Cisco says its PSIRT became aware of active exploitation in September 2026.
  • CISA’s read: the CISA coordinator’s SSVC entry lists exploitation as active, automatable as yes, and technical impact as total.
  • Forensics: the KEV entry carries CISA’s forensic-triage flag. Known ransomware use is listed as unknown.
  • How it was found: Cisco says the flaw surfaced while resolving a TAC support case. That means it came out of a customer problem, not a routine code review.
  • Detection: Cisco lists Snort rules 67109 and 67110 for this advisory.

No outlet we read attributes the exploitation to a named threat actor, and Cisco hasn’t disclosed how many devices or customers were hit. Treat any figure you see for those as unconfirmed.

How the Attack Works: What Cisco Says and What It Doesn’t

Cisco’s description gives the shape of the attack and withholds the details. Here is the path as Cisco states it.

  1. An attacker sends a crafted email message through an affected gateway.
  2. The email contains malicious SQL statements.
  3. Email-parsing logic fails to validate them.
  4. The SQL executes, and that leads to command execution as root.

Cisco does not say which part of the message carries the SQL, which database sits behind the gateway, or how a database statement turns into root on the host. We can’t show you the vulnerable code, because AsyncOS is closed-source.

CVE-2026-76461 attack path in four steps as Cisco states it: crafted email through the gateway, malicious SQL inside the message, insufficient validation in email parsing, SQL execution leading to root commands, with three details Cisco has not disclosed
The attack path Cisco confirms, and the three details it doesn’t

The generic bug class is easy to describe, though. This is an illustration of SQL injection in a mail-processing path, not Cisco’s code:

# Illustrative only. NOT Cisco's code; AsyncOS is closed-source.
# Vulnerable pattern: a value taken from the message is pasted into the query.
cursor.execute("SELECT * FROM senders WHERE address = '" + sender + "'")

# Safe pattern: the value is passed as a parameter, never as SQL text.
cursor.execute("SELECT * FROM senders WHERE address = %s", (sender,))

One thing in Cisco’s advisory is worth reading closely. Its indicator-of-compromise search is for the string COPY ... TO PROGRAM. Per the PostgreSQL documentation, COPY ... TO PROGRAM executes a shell command on the database server, requires superuser or the pg_execute_server_program role, and runs as the operating system user the database server runs under.

Our inference, not Cisco’s: that string suggests the backend is PostgreSQL or compatible with its syntax. Cisco doesn’t name the database. It also says commands run as root, and it doesn’t explain how SQL execution reaches root. We won’t guess at that step.

Who Is Affected and Which Builds Fix It

All Cisco Secure Email Gateway software on these release trains is affected until it reaches the first fixed release:

Release trainFirst fixed release
15.5 and earlier15.5.5-014
16.016.0.4-302
16.516.5.0-780

Cisco strongly recommends that anyone on a release earlier than 16.5 migrate to 16.5.0-780. NVD’s configuration data agrees with these boundaries.

For the cloud service, Cisco says it has already upgraded all Secure Email Cloud devices to 16.5.0-780. It also says it directly contacted customers whose cloud devices showed malicious activity. That is Cisco’s statement that exploitation touched cloud customers too.

CVE-2026-76461 fix and check card: fixed releases 15.5.5-014, 16.0.4-302 and 16.5.0-780, no workarounds, one grep for COPY TO PROGRAM in mail_logs, and a warning that root access can hide evidence
Fixed releases, the one indicator Cisco gives, and why it isn’t enough

Fixing CVE-2026-76461

Work through these in order:

  1. Upgrade. Use the System Upgrade options in the web interface, or upgrade then DOWNLOADINSTALL from the CLI. The device reboots afterward.
  2. Don’t wait on a workaround. Cisco says none exists.
  3. Apply Cisco’s hardening list anyway. Keep the appliance off the internet where you can, separate mail and management onto different interfaces, put it behind a filtering firewall, disable HTTP for the admin portal, and send logs to an external server.
  4. Then check for compromise, covered next.

One caution on step 3. Separating mail and management interfaces limits who can reach the admin side. CVE-2026-76461 arrives on the mail path, so by our reading that advice reduces your overall exposure but doesn’t close this bug. Only the upgrade does.

Hunting for CVE-2026-76461 Exploitation

Cisco’s own check is to review mail_logs for suspicious SQL statements, on every device if you run a cluster. Its example, which it calls non-exhaustive:

cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]

Any output may indicate malicious activity. Three limits apply, all from Cisco’s own text:

  • The example is not exhaustive. A clean result isn’t proof of a clean device.
  • Root access lets attackers hide. Cisco says evidence and indicators may be removed or hidden.
  • Cloud administrators may not be able to run it. Without CLI access you can’t check independently, and Cisco says it contacted affected cloud customers itself.

Because the device itself can’t be trusted after a root compromise, Cisco recommends cross-checking network and firewall logs outside it. Look for unexpected uploads from the gateway to external addresses, and downloads from malicious ones.

If you suspect exploitation:

  • Physical appliance: contact Cisco TAC, with remote access enabled, and let them investigate.
  • Virtual appliance: record forensics information first, because deploying a new instance destroys configuration and logs. Then deploy a fresh VM on a fixed release, rebuild the configuration, and renew credentials and cryptographic material.
  • Clusters: Cisco warns that private SSH keys used between cluster members could be accessed on a compromised appliance, which may let the attacker reach the other members. It recommends restoring every member of a cluster that contains at least one compromised device.

What a Root-Level Compromise via CVE-2026-76461 Puts at Risk

Cisco’s advice for a suspected compromise tells you what it thinks is exposed. It says to renew credentials and cryptographic materials installed on the appliance, and it warns that private SSH keys used between cluster members could be read. Anything stored on the box should be treated as taken.

Our assumption about a typical deployment, not a claim from the advisory: a gateway may hold directory lookup credentials, TLS certificates and private keys, administrator accounts, and the routing and policy configuration for your mail flow. The second-order risk is the one worth planning for. A gateway that sits in the mail path can see the mail passing through it, and an attacker with root can see it too. Cisco doesn’t say attackers did this, and a third-party analysis from the Cloud Security Alliance lists reading mail in transit as a potential outcome, labeled as its own analysis.

That’s why the rebuild guidance matters more than the patch. Patching CVE-2026-76461 closes the door. It doesn’t remove an attacker who is already inside.

A First-Hour Plan for CVE-2026-76461

If you run a Secure Email Gateway and haven’t upgraded:

  1. Confirm your release against the CVE-2026-76461 fixed builds in the table above, and note which devices are in a cluster.
  2. Start forensics capture before you change anything, especially on virtual appliances, since a replacement VM destroys logs.
  3. Run the mail_logs check on every device and save the output, even if it is empty.
  4. Pull outside logs from your firewall and network tooling for the gateway’s address, looking for transfers you can’t explain.
  5. Upgrade to a fixed release, or rebuild on one if anything looked wrong.
  6. Renew credentials and keys, starting with anything that was configured on the appliance.

A Pattern: Mail Security Appliances Keep Reaching KEV

CVE-2026-76461 isn’t the first unauthenticated root-level bug in this product line. CVE-2025-20393, in the Spam Quarantine feature of AsyncOS for Secure Email Gateway and the web manager, was added to KEV on December 17, 2025, and NVD describes it as unauthenticated command execution with root privileges. That makes two such entries in under ten months.

Cisco itself is a frequent KEV name right now. Counting from CISA’s JSON, Cisco had six entries between July 29 and September 30, 2026: CVE-2026-20316, CVE-2026-20349, CVE-2026-20079, CVE-2026-76461, CVE-2026-76460 and CVE-2026-76504. We cover two of the others in our write-ups on Cisco ISE CVE-2026-76460 and Cisco Catalyst SD-WAN Manager CVE-2026-76504.

And Cisco isn’t alone in mail security. On October 1, CISA added a FortiMail path traversal to KEV. We aren’t claiming a coordinated campaign, only that the catalog shows internet-facing mail gateways being exploited twice in three weeks.

How XHack Reads CVE-2026-76461

The testing lesson from CVE-2026-76461 is about where input enters a system. Most security testing starts at the login page and the admin console. A mail gateway’s biggest attack surface is the mail it parses: addresses, headers, subjects, attachments and anything else a message carries into a database or a shell.

That surface is testable, with permission. Our AI VAPT services include testing how internet-facing systems handle hostile input on paths that aren’t the obvious login, and checking whether management interfaces are reachable from places they shouldn’t be. A pentest report documents what was tested and found. It doesn’t certify that a product is free of a given vulnerability.

If you run a Cisco gateway, patching comes first, then the log checks above, then a look at what else in your mail path accepts input from strangers.

FAQ: CVE-2026-76461 Questions Answered

What is CVE-2026-76461?

CVE-2026-76461 is a CVSS 9.8 SQL injection in the email parsing of Cisco AsyncOS for Cisco Secure Email Gateway. An unauthenticated remote attacker can send a crafted email containing malicious SQL statements, which leads to command execution as root.

Is CVE-2026-76461 being exploited?

Yes. Cisco says its PSIRT became aware of active exploitation in September 2026, and CISA added it to the Known Exploited Vulnerabilities catalog on September 14, 2026 with a September 17 deadline and a forensic-triage flag.

Which versions does CVE-2026-76461 affect?

Cisco Secure Email Gateway on release 15.5 and earlier, 16.0, and 16.5 before their first fixed releases: 15.5.5-014, 16.0.4-302 and 16.5.0-780. Physical and virtual appliances are affected regardless of configuration.

Is there a workaround for CVE-2026-76461?

No. Cisco says no workaround addresses this vulnerability, and the fix is a software upgrade. Cisco recommends 16.5.0-780 for anything earlier than 16.5.

How do I check for CVE-2026-76461 exploitation?

Search mail_logs for suspicious SQL, such as COPY.*TO PROGRAM, on every device in a cluster. Cisco calls this non-exhaustive and warns that root access may let attackers hide evidence, so also review firewall and network logs for unexpected transfers to or from the gateway.

Does CVE-2026-76461 affect Secure Email Cloud?

Cisco says it upgraded all Secure Email Cloud devices to 16.5.0-780, and that it directly contacted customers whose cloud devices showed malicious activity.

Does CVE-2026-76461 affect Secure Email and Web Manager?

No. Cisco lists Secure Email and Web Manager and Secure Web Appliance as not vulnerable to this bug.

The Bottom Line

CVE-2026-76461 turns the gateway’s core job, reading mail from strangers, into the attack path. Cisco says exploiting CVE-2026-76461 needs no login, no special configuration and no user interaction, and offers one fix: upgrade.

Upgrade to 15.5.5-014, 16.0.4-302 or 16.5.0-780, check mail_logs and your outside logs, and if anything looks wrong, preserve evidence before you rebuild. A clean grep on a device that may have had root access is weaker evidence than it looks.


Categories

News

Previous

XHack AI Can Make Mistakes: What Goes Wrong, Why, and How to Catch It

Next

Bug Bounty vs Freelance Pentesting: Which Pays Better in 2026?

On this page

Why a Bug in an Email Gateway Is Different

What CVE-2026-76461 Is, According to Cisco

How the Attack Works: What Cisco Says and What It Doesn’t

Who Is Affected and Which Builds Fix It

Fixing CVE-2026-76461

Hunting for CVE-2026-76461 Exploitation

What a Root-Level Compromise via CVE-2026-76461 Puts at Risk

A First-Hour Plan for CVE-2026-76461

A Pattern: Mail Security Appliances Keep Reaching KEV

How XHack Reads CVE-2026-76461

FAQ: CVE-2026-76461 Questions Answered

What is CVE-2026-76461?

Is CVE-2026-76461 being exploited?

Which versions does CVE-2026-76461 affect?

Is there a workaround for CVE-2026-76461?

How do I check for CVE-2026-76461 exploitation?

Does CVE-2026-76461 affect Secure Email Cloud?

Does CVE-2026-76461 affect Secure Email and Web Manager?

The Bottom Line

Related articles

Continue reading

CVE-2026-93616: The Critical Check Point Management Server Zero-Day

News

CVE-2026-93616: The Critical Check Point Management Server Zero-Day

CVE-2026-93616 is a CVSS 9.8 pre-auth zero-day in Check Point Security Management, exploited since July 23. Affected ver...

Read article
CVE-2026-82042: The Critical UTMStack Flaw Where One Shared Key Was Admin

News

CVE-2026-82042: The Critical UTMStack Flaw Where One Shared Key Was Admin

CVE-2026-82042 and CVE-2026-82041 are critical UTMStack SIEM flaws: one shared key acted as admin, and no role check gua...

Read article
CVE-2026-102489: How a Critical Zammad Chain Gave an Attacker Root in Seconds

News

CVE-2026-102489: How a Critical Zammad Chain Gave an Attacker Root in Seconds

CVE-2026-102489 and CVE-2026-102490 chain a Zammad session hijack into root, and CISA says both are exploited. What̵...

Read article