CYBER DELTA FORCESearch
VulnerabilitiesDEVELOPING

Cisco Secure Email Gateway zero-day exploited to gain root command execution

Cisco says a critical AsyncOS vulnerability in Secure Email Gateway is being actively exploited. CVE-2026-76461 can let an unauthenticated remote attacker turn a crafted email into arbitrary command execution with root privileges on the appliance.

CDF News DeskThe Hacker News15 Sept 2026, 11:41 am
Image courtesy of The Hacker News. Original report
CDF REPORT

Cisco Secure Email Gateway is designed to inspect one of the most common inputs into an enterprise: email. That makes a newly disclosed vulnerability in its parsing layer particularly serious. Cisco says CVE-2026-76461 is already being exploited in the wild and can give an unauthenticated remote attacker root-level command execution on an affected gateway.

The attack does not begin with stolen credentials or an administrator clicking a malicious link. According to Cisco, an attacker can send a crafted email containing malicious SQL statements through the gateway. The vulnerability is caused by insufficient validation in the email-parsing logic, and successful exploitation can move from the crafted message to arbitrary SQL execution and then to commands running as root on the underlying operating system.

Cisco rates the vulnerability 9.8 out of 10 and says it affects both physical and virtual Secure Email Gateway deployments regardless of configuration. That scope matters because the product normally operates at the boundary of an organization's email environment. A compromise therefore deserves to be considered an infrastructure incident, not simply another endpoint vulnerability waiting in a patch queue.

The vendor has released fixes and says there is no workaround that addresses the vulnerability. The first fixed release is 15.5.5-014 for AsyncOS 15.5 and earlier, 16.0.4-302 for the 16.0 branch, and 16.5.0-780 for 16.5. Cisco recommends moving to 16.5.0-780. Security teams should first establish exactly which appliances are running in their environment, including virtual deployments that may be less visible in traditional hardware inventories.

There is also an incident-response question. Cisco specifically recommends reviewing mail_logs for suspicious SQL statements when checking for attempted exploitation. That log review should be correlated with network and management-plane telemetry so defenders can distinguish an attempted exploit from a successful compromise. If suspicious activity is found, Cisco recommends restoring a secure configuration and renewing credentials and cryptographic materials where possible.

Cisco says it became aware of active exploitation in September. For Cisco Secure Email Cloud, the company says it conducted a threat-intelligence investigation, contacted customers where indicators of possible compromise were identified and deployed mitigations within its managed environment. That is a useful distinction for defenders: a cloud service may have vendor-side remediation that does not exist for an on-premises or customer-managed appliance.

For now, the most important question for an organization running Secure Email Gateway is simple: are we patched, and do our logs show evidence that someone tried to exploit us? A fixed release closes the known vulnerability; it does not by itself prove that an already-compromised appliance is clean. CDF will track further exploitation evidence, new indicators and changes to Cisco's guidance as this developing incident evolves.

What changed

Cisco has moved the issue from a newly disclosed vulnerability into an active-exploitation incident and has published fixed releases for affected AsyncOS branches.

The vendor recommends upgrading to a fixed release and specifically recommends migrating to AsyncOS 16.5.0-780 where practical.

Who is affected

Cisco says both physical and virtual Secure Email Gateway deployments are affected, regardless of device configuration.

Cisco Secure Email and Web Manager and Cisco Secure Web Appliance are not affected by this specific vulnerability.

Why this matters

The attack path is unusually direct: no account is required and the initial input can arrive as an email processed by a perimeter security appliance.

Because successful exploitation reaches root on the appliance, defenders should treat suspicious activity as a potential appliance compromise rather than only a patch-management item.

The technical picture

CVE-2026-76461 is classified as CWE-89 SQL injection and has a CVSS base score of 9.8. Cisco attributes the issue to insufficient validation in email-parsing logic.

Cisco says an attacker can send a crafted email containing malicious SQL statements through the affected device. Successful exploitation can allow arbitrary SQL statements and ultimately command execution with root privileges.

How organizations are responding

Cisco released fixed software and says there are no workarounds for the underlying flaw.

The vendor recommends 15.5.5-014 for 15.5 and earlier, 16.0.4-302 for the 16.0 branch, and 16.5.0-780 for the 16.5 branch. Cisco recommends migrating to 16.5.0-780.

For Cisco Secure Email Cloud, Cisco says it investigated customer devices, contacted customers where indicators of possible compromise were found, and deployed mitigations under its management.

What defenders should do now

Inventory all Cisco Secure Email Gateway physical and virtual appliances and verify their AsyncOS versions against Cisco's fixed-release table.

Upgrade affected appliances to a fixed release as a priority; do not rely on a workaround because Cisco says none addresses the vulnerability.

Review mail_logs for suspicious SQL statements and correlate the results with firewall, network and management-plane telemetry.

If exploitation is suspected, restore the appliance to a secure configuration and renew credentials and cryptographic material where possible, following Cisco's incident-response guidance.

What to watch next

Watch for additional indicators of compromise, exploitation reporting and revised Cisco guidance as the investigation develops.

Watch for confirmation that affected environments have been upgraded and for any changes to the fixed-release guidance.

What remains unknown

Cisco has confirmed active exploitation but has not publicly identified the threat actor behind the activity in the advisory.

Public reporting does not establish a complete count of compromised customer appliances.

MORE IN VULNERABILITIES

More cybersecurity reporting

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 ReleasesSecurityWeek · 15 Sept 2026, 4:36 pm4 in 5 Singapore Business Websites Have WordPress VulnerabilitiesThe Cyber Express · 15 Sept 2026, 1:53 pm'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops BlinkDark Reading · 15 Sept 2026, 3:07 amHomebrew 7.0.0 gets built-in GUI, better security controlsBleepingComputer · 15 Sept 2026, 1:21 am