Threat Insight
Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild (CVE-2026-76461)
Cisco has published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. If exploited, the vulnerability could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance by sending a specially crafted email through a vulnerable gateway[1].
Cisco Secure Email Gateway processes inbound and outbound email traffic as part of normal operation. According to Cisco[1], exploitation does not require authentication or access to an administrative interface. An attacker can reportedly trigger the vulnerability through malicious email content processed by the gateway.
Cisco has stated that it became aware of active exploitation in September 2026, indicating that the vulnerability was exploited prior to public disclosure. [1]
CVE
CVE-2026-76461
Affected Products
Cisco Secure Email Gateway (Cisco AsyncOS Software) versions[1]:
15.5 and earlier
16.0
16.5
Exploitation
Cisco confirms active exploitation during September 2026[1].
The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Recommended Actions
Truesec recommends that you upgrade to one of the fixed versions below.
The vulnerability is fixed in Cisco Secure Email Gateway (Cisco AsyncOS Software) versions[1]:
15.5.5-014
16.0.4-302
16.5.0-780
Detection
To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device. The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs[1]:
cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]
The presence of any entry in the output may indicate malicious activity[1].
References
Stay ahead with cyber insights
Newsletter
Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.
Your current browser privacy settings may be preventing this form from loading properly. To continue, please allow cookies/tracking for this site or temporarily disable strict privacy protection, then refresh the page.
If you’re still experiencing issues, please contact us at hello@truesec.com