---
schema: 1
kind: vulnerability
title: "CVE-2026-76461: Cisco Secure Email Gateway unauthenticated SQL injection in email parsing reaches root command execution, exploited before disclosure (CVSS 9.8)"
headline: "Cisco's mail gateway can be rooted by a single crafted email, and Cisco found out from a real customer's compromise"
summary: >
  Cisco disclosed CVE-2026-76461 (CVSS 9.8) on 2026-09-14: an unauthenticated attacker who sends a
  single crafted email containing SQL statements to a Cisco Secure Email Gateway can execute
  arbitrary OS commands as root. Cisco confirms active exploitation and found the flaw while
  investigating a customer's compromise; there is no workaround. CISA added it to its Known
  Exploited Vulnerabilities catalog the same day with a three-day remediation deadline. Cisco
  simultaneously shipped a hardening release fixing five further internally-found vulnerabilities
  in the same product, none reported exploited.
discovered_at: "2026-09-15T04:35:00Z"
updated_at: null
event_date: "2026-09-14"
run_id: 2026-09-15T0410Z-intel
priority: critical
immediate_action:
  title: "Patch every Cisco Secure Email Gateway now: unauthenticated root RCE via a single email, already exploited"
  action: >
    A remote, unauthenticated attacker gains root on the appliance by sending it one crafted email;
    there is no workaround and no mitigation short of upgrading. Cisco itself found this
    investigating a live customer compromise, and CISA's own KEV deadline gives just three days
    (due 2026-09-17). Upgrade every physical and virtual Secure Email Gateway appliance today and
    hunt mail_logs for the exploitation pattern before assuming a device is clean.
tags: [vulnerabilities, actively-exploited, pre-auth, rce, sqli, zero-click, cisa-kev, patch-available]
regions: [global]
sectors: [public-sector, technology]
entities: ["product:cisco-secure-email-gateway"]
techniques: [T1190]
affected_products: ["Cisco Secure Email Gateway", "Cisco Secure Email and Web Manager"]
cves:
  - id: CVE-2026-76461
    cvss: "9.8"
    epss: null
    type: sqli
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "AsyncOS for Cisco Secure Email Gateway 15.5 and earlier, 16.0, and 16.5, physical and virtual appliances, regardless of configuration"
    fixed: "15.5.5-014 (15.5 and earlier) / 16.0.4-302 (16.0) / 16.5.0-780 (16.5, Cisco's recommended target); no workaround exists short of upgrading"
  - id: CVE-2026-76440
    cvss: "9.8"
    epss: null
    type: path-traversal
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Cisco Secure Email Gateway and Secure Email and Web Manager, all configurations, from the September 2026 internal hardening review (not reported exploited)"
    fixed: "Gateway: 15.5.5-014 / migrate off 16.0 / 16.5.0-780. Web Manager: 15.5.5-006 / migrate off 16.0 / 16.5.0-429"
  - id: CVE-2026-76441
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Cisco Secure Email Gateway and Secure Email and Web Manager, all configurations; grouped under CWE-284 (Cisco's own grouping covers authorization, authentication, privileges, and bypasses, without specifying which applies to this CVE ID) from the September 2026 internal hardening review (not reported exploited)"
    fixed: "Gateway: 15.5.5-014 / migrate off 16.0 / 16.5.0-780. Web Manager: 15.5.5-006 / migrate off 16.0 / 16.5.0-429"
  - id: CVE-2026-20353
    cvss: "9.8"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Cisco Secure Email Gateway and Secure Email and Web Manager, all configurations; grouped under CWE-664 (Cisco's own grouping covers uncontrolled resource consumption, algorithmic complexity, recursion/iteration, deserialization, and improper resource initialization, without specifying which applies to this CVE ID) from the September 2026 internal hardening review (not reported exploited)"
    fixed: "Gateway: 15.5.5-014 / migrate off 16.0 / 16.5.0-780. Web Manager: 15.5.5-006 / migrate off 16.0 / 16.5.0-429"
  - id: CVE-2026-76443
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Cisco Secure Email Gateway and Secure Email and Web Manager, all configurations; a separate finding from the same September 2026 internal hardening review, grouped under CWE-707, which Cisco's own table describes as covering command, SQL, and code/eval injection, and cross-site scripting collectively, without stating which applies to this CVE ID specifically; not the exploited CVE-2026-76461, which Cisco confirms is a distinct, separately-tracked SQL-injection CVE (Cisco states this grouped CVE is not itself known to be exploited)"
    fixed: "Gateway: 15.5.5-014 / migrate off 16.0 / 16.5.0-780. Web Manager: 15.5.5-006 / migrate off 16.0 / 16.5.0-429"
  - id: CVE-2026-76442
    cvss: "7.5"
    epss: null
    type: dos
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Cisco Secure Email Gateway and Secure Email and Web Manager, all configurations, from the September 2026 internal hardening review (not reported exploited)"
    fixed: "Gateway: 15.5.5-014 / migrate off 16.0 / 16.5.0-780. Web Manager: 15.5.5-006 / migrate off 16.0 / 16.5.0-429"
sources:
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX"
    publisher: "Cisco PSIRT"
    date: "2026-09-14"
    role: primary
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities catalog (catalogue version 2026.09.14)"
    date: "2026-09-14"
    role: primary
  - url: "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
    publisher: "Cisco PSIRT (hardening-release advisory)"
    date: "2026-09-14"
    role: corroborating
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0368"
    publisher: "NCSC-NL"
    date: "2026-09-14"
    role: corroborating
closed_sources: []
evidence:
  - quote: "A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system."
    publisher: "Cisco PSIRT"
  - quote: "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability."
    publisher: "Cisco PSIRT"
  - quote: "This vulnerability was found during the resolution of a Cisco TAC support case."
    publisher: "Cisco PSIRT"
  - quote: "grep -i \"COPY.*TO PROGRAM\" [IronPort Text Mail Logs Log name - Default: mail_logs]"
    publisher: "Cisco PSIRT"
  - quote: "These vulnerabilities were found during internal security testing using existing testing processes as well as frontier AI models."
    publisher: "Cisco PSIRT (hardening-release advisory)"
  - quote: "Cisco reports that successful exploitation of this vulnerability has been observed. (translated from Dutch)"
    original: "Cisco meldt dat succesvolle exploitatie van deze kwetsbaarheid is waargenomen."
    publisher: "NCSC-NL"
  - quote: "The CVSS score that is assigned to each CVE ID represents the maximum potential severity of the single most impactful underlying vulnerability within that specific CWE category."
    publisher: "Cisco PSIRT (hardening-release advisory)"
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 1
watchlist_hit: false
actions:
  - "Upgrade every Cisco Secure Email Gateway appliance (physical and virtual) to AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780 (Cisco's recommended target) now; the same upgrade also closes the five hardening-release CVEs (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443, CVE-2026-76442) Cisco shipped the same day."
  - "Grep every appliance's mail_logs (and, if clustered, every cluster member's logs) for the pattern \"COPY.*TO PROGRAM\" and cross-check firewall/network logs external to the appliance for unexpected outbound connections; a successful exploit grants root, so an attacker may have removed local log evidence of their own access."
  - "Secure Email Cloud customers should confirm directly with Cisco whether their instance is among those where indicators of compromise were identified; Cisco states it has already proactively contacted affected Cloud customers and upgraded all Cloud instances."
updates: []
migrated_from: null
---

Cisco's own advisory names the mechanism plainly: insufficient validation in the email-parsing logic of AsyncOS lets an unauthenticated remote attacker send a single crafted email containing SQL statements through the device, and "a successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system" ([Cisco PSIRT, 2026-09-14](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX)). CVE-2026-76461 (CVSS 9.8) affects every Cisco Secure Email Gateway, physical and virtual, regardless of configuration; Cisco confirms Secure Email and Web Manager and Secure Web Appliance are not affected by this specific flaw. There is no workaround; the only remediation is upgrading to AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780, the release Cisco "strongly recommends" migrating to.

Two details in Cisco's own wording raise this above a routine emergency patch. First, Cisco states the vulnerability "was found during the resolution of a Cisco TAC support case" (meaning it surfaced from a real customer's compromise investigation, not internal fuzzing), and that it has already directly contacted Secure Email Cloud customers on whose devices indicators of compromise were found, having upgraded all Cloud instances itself ([Cisco PSIRT, 2026-09-14](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX)). Second, CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day, giving it a three-day remediation deadline (due 2026-09-17) and flagging it for Forensic Triage Requirements ([CISA KEV, catalogue version 2026.09.14](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)); NCSC-NL's own advisory relays the same exploitation claim: "Cisco reports that successful exploitation of this vulnerability has been observed" (translated from Dutch) ([NCSC-NL, NCSC-2026-0368, 2026-09-14](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0368)). Because a successful exploit grants root, Cisco itself warns that local log evidence of exploitation may have been removed by the attacker, and recommends cross-checking firewall and network logs external to the appliance rather than relying on the device's own logs alone.

The same day, Cisco shipped a companion "Security Hardening Release" advisory for the identical product line, bundling five further internally-discovered vulnerabilities that Cisco groups by CWE class rather than by individual flaw: a path-traversal grouping (CVE-2026-76440, CVSS 9.8), an improper-access-control grouping (CVE-2026-76441, CVSS 9.8), an uncontrolled-resource-consumption grouping (CVE-2026-20353, CVSS 9.8), a second injection-class grouping (CVE-2026-76443, CVSS 9.8, explicitly distinct from the exploited CVE-2026-76461 despite sharing the same top-level weakness class) and an input-validation grouping (CVE-2026-76442, CVSS 7.5). Cisco's own table states that "the CVSS score that is assigned to each CVE ID represents the maximum potential severity of the single most impactful underlying vulnerability within that specific CWE category," so the four identical 9.8 scores reflect an assigned ceiling per grouping rather than four independently-confirmed critical bugs. Unlike the exploited flaw, this bundle also affects Secure Email and Web Manager, and Cisco states none of the five is known to be exploited or publicly disclosed elsewhere. Notably, Cisco attributes discovery of this bundle to "internal security testing using existing testing processes as well as frontier AI models" ([Cisco PSIRT, hardening-release advisory, 2026-09-14](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm)). Administrators who upgrade against the exploited CVE close all six CVEs with the same action, since both advisories share identical fixed releases for Secure Email Gateway.

**Defender takeaway:** treat every internet-facing Cisco Secure Email Gateway as potentially already compromised until patched and checked; Cisco's own detection guidance and the compressed KEV deadline both signal this is being actively used against real environments right now, not a theoretical risk. **Triage:** Cisco's own discriminator is the mail_logs pattern `COPY.*TO PROGRAM`; any hit is evidence of attempted or successful SQL-injection exploitation and warrants full incident response, not just a patch, since a successful hit implies root-level compromise and possible log tampering.
