
Table of contents
19
Read this in 30 seconds: CVE-2026-76461 is a CVSS 9.8 SQL injection in Cisco Secure Email Gateway that lets an unauthenticated attacker run commands as root, and Cisco says it is being exploited.
- The attack arrives as ordinary mail. Cisco says an attacker sends a crafted email containing malicious SQL statements through an affected device. No login and no management access are involved.
- Configuration doesn’t protect you. Cisco says the bug affects physical and virtual gateways “regardless of device configuration,” and there are no workarounds.
- The only fix is an upgrade. Move to 15.5.5-014, 16.0.4-302 or 16.5.0-780. Cisco recommends 16.5.0-780 for anything earlier than 16.5.
- Root access means the logs may lie. Cisco warns that evidence of exploitation may be removed or hidden, so check network and firewall logs outside the device too.
- CISA flagged it for forensic triage. Added to KEV on September 14, due September 17, which was 20 days ago.
An email gateway exists to accept untrusted messages from strangers, so a bug in how it reads them is a bug in its whole purpose.
Cisco published advisory cisco-sa-esa-inj-2bLVGmhX for CVE-2026-76461 on September 14, 2026, rated Critical. CISA added it to the Known Exploited Vulnerabilities catalog the same day with a three-day deadline.
This article covers what Cisco confirms, what it leaves unsaid about how the bug works, who is affected, the fixed builds, and how to check a gateway that may already have been hit.

Most critical bugs live in something an attacker has to find and reach: a login page, a management port, an API. A secure email gateway sits in the mail path and reads every message that crosses it. The input to CVE-2026-76461 is the thing the product is built to process.
That has three consequences, and Cisco’s advisory supports each of them.
CVE-2026-76461 affects Cisco Secure Email Gateway, both physical and virtual, and Cisco’s Secure Email Cloud service includes gateway devices, so it is in scope too. Cisco lists Secure Email and Web Manager and Secure Web Appliance as not vulnerable.
Cisco attributes the flaw to “insufficient validation in the email parsing logic.” A successful attack lets the attacker run arbitrary SQL statements, which leads to command execution with root privileges on the underlying operating system.
What we can confirm from primary sources:
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The score comes from Cisco, not from NVD’s own analysts.No outlet we read attributes the exploitation to a named threat actor, and Cisco hasn’t disclosed how many devices or customers were hit. Treat any figure you see for those as unconfirmed.
Cisco’s description gives the shape of the attack and withholds the details. Here is the path as Cisco states it.
Cisco does not say which part of the message carries the SQL, which database sits behind the gateway, or how a database statement turns into root on the host. We can’t show you the vulnerable code, because AsyncOS is closed-source.

The generic bug class is easy to describe, though. This is an illustration of SQL injection in a mail-processing path, not Cisco’s code:
# Illustrative only. NOT Cisco's code; AsyncOS is closed-source.
# Vulnerable pattern: a value taken from the message is pasted into the query.
cursor.execute("SELECT * FROM senders WHERE address = '" + sender + "'")
# Safe pattern: the value is passed as a parameter, never as SQL text.
cursor.execute("SELECT * FROM senders WHERE address = %s", (sender,))
One thing in Cisco’s advisory is worth reading closely. Its indicator-of-compromise search is for the string COPY ... TO PROGRAM. Per the PostgreSQL documentation, COPY ... TO PROGRAM executes a shell command on the database server, requires superuser or the pg_execute_server_program role, and runs as the operating system user the database server runs under.
Our inference, not Cisco’s: that string suggests the backend is PostgreSQL or compatible with its syntax. Cisco doesn’t name the database. It also says commands run as root, and it doesn’t explain how SQL execution reaches root. We won’t guess at that step.
All Cisco Secure Email Gateway software on these release trains is affected until it reaches the first fixed release:
| Release train | First fixed release |
|---|---|
| 15.5 and earlier | 15.5.5-014 |
| 16.0 | 16.0.4-302 |
| 16.5 | 16.5.0-780 |
Cisco strongly recommends that anyone on a release earlier than 16.5 migrate to 16.5.0-780. NVD’s configuration data agrees with these boundaries.
For the cloud service, Cisco says it has already upgraded all Secure Email Cloud devices to 16.5.0-780. It also says it directly contacted customers whose cloud devices showed malicious activity. That is Cisco’s statement that exploitation touched cloud customers too.

Work through these in order:
upgrade then DOWNLOADINSTALL from the CLI. The device reboots afterward.One caution on step 3. Separating mail and management interfaces limits who can reach the admin side. CVE-2026-76461 arrives on the mail path, so by our reading that advice reduces your overall exposure but doesn’t close this bug. Only the upgrade does.
Cisco’s own check is to review mail_logs for suspicious SQL statements, on every device if you run a cluster. Its example, which it calls non-exhaustive:
cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]
Any output may indicate malicious activity. Three limits apply, all from Cisco’s own text:
Because the device itself can’t be trusted after a root compromise, Cisco recommends cross-checking network and firewall logs outside it. Look for unexpected uploads from the gateway to external addresses, and downloads from malicious ones.
If you suspect exploitation:
Cisco’s advice for a suspected compromise tells you what it thinks is exposed. It says to renew credentials and cryptographic materials installed on the appliance, and it warns that private SSH keys used between cluster members could be read. Anything stored on the box should be treated as taken.
Our assumption about a typical deployment, not a claim from the advisory: a gateway may hold directory lookup credentials, TLS certificates and private keys, administrator accounts, and the routing and policy configuration for your mail flow. The second-order risk is the one worth planning for. A gateway that sits in the mail path can see the mail passing through it, and an attacker with root can see it too. Cisco doesn’t say attackers did this, and a third-party analysis from the Cloud Security Alliance lists reading mail in transit as a potential outcome, labeled as its own analysis.
That’s why the rebuild guidance matters more than the patch. Patching CVE-2026-76461 closes the door. It doesn’t remove an attacker who is already inside.
If you run a Secure Email Gateway and haven’t upgraded:
mail_logs check on every device and save the output, even if it is empty.CVE-2026-76461 isn’t the first unauthenticated root-level bug in this product line. CVE-2025-20393, in the Spam Quarantine feature of AsyncOS for Secure Email Gateway and the web manager, was added to KEV on December 17, 2025, and NVD describes it as unauthenticated command execution with root privileges. That makes two such entries in under ten months.
Cisco itself is a frequent KEV name right now. Counting from CISA’s JSON, Cisco had six entries between July 29 and September 30, 2026: CVE-2026-20316, CVE-2026-20349, CVE-2026-20079, CVE-2026-76461, CVE-2026-76460 and CVE-2026-76504. We cover two of the others in our write-ups on Cisco ISE CVE-2026-76460 and Cisco Catalyst SD-WAN Manager CVE-2026-76504.
And Cisco isn’t alone in mail security. On October 1, CISA added a FortiMail path traversal to KEV. We aren’t claiming a coordinated campaign, only that the catalog shows internet-facing mail gateways being exploited twice in three weeks.
The testing lesson from CVE-2026-76461 is about where input enters a system. Most security testing starts at the login page and the admin console. A mail gateway’s biggest attack surface is the mail it parses: addresses, headers, subjects, attachments and anything else a message carries into a database or a shell.
That surface is testable, with permission. Our AI VAPT services include testing how internet-facing systems handle hostile input on paths that aren’t the obvious login, and checking whether management interfaces are reachable from places they shouldn’t be. A pentest report documents what was tested and found. It doesn’t certify that a product is free of a given vulnerability.
If you run a Cisco gateway, patching comes first, then the log checks above, then a look at what else in your mail path accepts input from strangers.
CVE-2026-76461 is a CVSS 9.8 SQL injection in the email parsing of Cisco AsyncOS for Cisco Secure Email Gateway. An unauthenticated remote attacker can send a crafted email containing malicious SQL statements, which leads to command execution as root.
Yes. Cisco says its PSIRT became aware of active exploitation in September 2026, and CISA added it to the Known Exploited Vulnerabilities catalog on September 14, 2026 with a September 17 deadline and a forensic-triage flag.
Cisco Secure Email Gateway on release 15.5 and earlier, 16.0, and 16.5 before their first fixed releases: 15.5.5-014, 16.0.4-302 and 16.5.0-780. Physical and virtual appliances are affected regardless of configuration.
No. Cisco says no workaround addresses this vulnerability, and the fix is a software upgrade. Cisco recommends 16.5.0-780 for anything earlier than 16.5.
Search mail_logs for suspicious SQL, such as COPY.*TO PROGRAM, on every device in a cluster. Cisco calls this non-exhaustive and warns that root access may let attackers hide evidence, so also review firewall and network logs for unexpected transfers to or from the gateway.
Cisco says it upgraded all Secure Email Cloud devices to 16.5.0-780, and that it directly contacted customers whose cloud devices showed malicious activity.
No. Cisco lists Secure Email and Web Manager and Secure Web Appliance as not vulnerable to this bug.
CVE-2026-76461 turns the gateway’s core job, reading mail from strangers, into the attack path. Cisco says exploiting CVE-2026-76461 needs no login, no special configuration and no user interaction, and offers one fix: upgrade.
Upgrade to 15.5.5-014, 16.0.4-302 or 16.5.0-780, check mail_logs and your outside logs, and if anything looks wrong, preserve evidence before you rebuild. A clean grep on a device that may have had root access is weaker evidence than it looks.
Categories
Related articles