Vulnerability
Published 2026-09-14
Verified 2026-09-19

Cisco Secure Email Gateway AsyncOS SQL injection to root (CVE-2026-76461); exploited; CVSS 9.8

Cisco PSIRT advisory cisco-sa-esa-inj-2bLVGmhX (14 September 2026) covers CVE-2026-76461, a Critical SQL injection in email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway (physical and virtual, any configuration). Unauthenticated remote attackers can send a crafted email with malicious SQL statements and gain command execution as root on the underlying OS. Cisco CVSS 3.1 base 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CWE-89; Bug CSCwu56234. Not affected: Secure Email and Web Manager, Secure Web Appliance. Cisco PSIRT became aware of active exploitation in September 2026; Cloud customers with detected malicious activity were contacted directly; Cloud fleet already upgraded to 16.5.0-780. IoC guidance: grep mail_logs for suspicious SQL (example COPY.*TO PROGRAM); also review external network/firewall logs because root access can erase on-box evidence. No workarounds. Fixed AsyncOS: 15.5 and earlier → 15.5.5-014; 16.0 → 16.0.4-302; 16.5 → 16.5.0-780 (Cisco strongly recommends 16.5.0-780). CISA added CVE-2026-76461 to KEV with FCEB remediation due 17 September 2026 (wire: BleepingComputer / THN 15 Sep). Same-day Cisco also shipped other critical SEG/SEWM fixes (CVE-2026-76440/76441/20353/76443) without claimed in-the-wild use — covered here only as context, not separate desk cards. Primary: Cisco PSIRT; wires: BleepingComputer, The Hacker News, SecurityWeek (15 Sep 2026).

Product
Cisco Secure Email Gateway (AsyncOS; physical and virtual appliances)
Versions
AsyncOS 15.5 and earlier (fix 15.5.5-014); 16.0 (fix 16.0.4-302); 16.5 (fix 16.5.0-780). Secure Email Cloud already on 16.5.0-780 per Cisco
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade AsyncOS to 15.5.5-014 / 16.0.4-302 / 16.5.0-780 (prefer 16.5.0-780); hunt mail_logs SQL IoCs and off-box network anomalies; if compromised, rebuild virtual appliances / engage TAC for physical

Primary: Cisco PSIRT cisco-sa-esa-inj-2bLVGmhX (CVE-2026-76461, 14 Sep 2026) · Vendor: Cisco Security Advisory — Secure Email Gateway SQL injection · CVE: CVE-2026-76461, CVE-2026-76440 · BleepingComputer (15 Sep 2026); also THN / SecurityWeek

vulnerabilities network cloud