Cisco Email Gateway Flaw CVE-2026-76461 Gives Root From One Crafted Message
Security / news
Cisco Email Gateway Flaw CVE-2026-76461 Gives Root From One Crafted Message
Cisco's advisory lists no workaround for the exploited SQL injection in AsyncOS, and cloud administrators without CLI access may not be able to check for themselves.

Cisco Secure Email Gateway appliances running AsyncOS 15.5 or earlier, 16.0 or 16.5 can be taken over by an unauthenticated attacker who sends one crafted email, and Cisco says attackers have done it. The flaw is CVE-2026-76461, rated 9.8 out of 10 on the CVSS severity scale. Cisco's advisory lists no workaround, so the remedy is a fixed release.
Cisco published the advisory (cisco-sa-esa-inj-2bLVGmhX) on Sept. 14, 2026, and CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day with a federal deadline of Sept. 17, according to The Hacker News. Cisco revised the advisory to its final version on Sept. 17. Cisco's own words on exploitation: "In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability."
What an attacker needs
Nothing, on the vector Cisco publishes: network access, low complexity, no privileges and no user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The bug is a SQL injection, tracked as CWE-89, in the email parsing logic of AsyncOS, the appliance operating system. A message containing malicious SQL statements leads to command execution as root on the underlying system.
The score is accurate here. Confidentiality, integrity and availability are all rated high because root on a mail gateway sees every message that passes through it. Cisco says the flaw applies to physical and virtual Secure Email Gateways regardless of configuration. Secure Email and Web Manager and Secure Web Appliance are not affected.
Which releases to install
| Affected release | First fixed release |
|---|---|
| 15.5 and earlier | 15.5.5-014 |
| 16.0 | 16.0.4-302 |
| 16.5 | 16.5.0-780 |
Cisco strongly recommends that customers on releases earlier than 16.5 move to 16.5.0-780. The Hacker News prints the first fixed 15.5 build as 15.5.5-0141; the table follows Cisco's advisory, so check the build string against Cisco before upgrading.

How to check whether an appliance was hit
Cisco tells administrators to review the mail_logs for suspicious SQL statements, and offers one non-exhaustive example: grep -i "COPY.*TO PROGRAM". Any matching entry may indicate malicious activity. On a cluster, every member's logs need reading.
Root access lets an attacker hide evidence on the device, so Cisco also says to cross-check network and firewall logs for unexpected uploads to external IP addresses or downloads from malicious ones. That advice carries a gap the advisory admits: Secure Email Cloud administrators without CLI access may not be able to run the checks themselves. Cisco says it has contacted directly the customers where it detected malicious activity.
Cisco has not said how many appliances were attacked, who is behind it, or when exploitation began beyond September 2026. The Sophos Counter Threat Unit advisory post repeats the 9.8 rating and Cisco's exploitation statement but reports no Sophos-observed attacks or indicators, and says SophosLabs will deliver detections as available.
The pattern across edge appliances
This is the second Cisco exploited flaw on this site in three weeks. The company's SD-WAN controller drew its own listing on Sept. 30, covered in our report on CVE-2026-76504. Another mail-security product followed on Oct. 1, with Fortinet's FortiMail path-traversal flaw added to CISA's list.
The practical order for a Secure Email Gateway owner is short: upgrade to 16.5.0-780 or the fixed build on your branch, run the mail_logs search on every node, and review firewall egress logs back to Sept. 14. The advisory's final revision on Sept. 17 is the latest Cisco has published.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 04Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.