Threat Insight

Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild (CVE-2026-76461)

Cisco has published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. If exploited, the vulnerability could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance by sending a specially crafted email through a vulnerable gateway[1].

  • Insight

Cisco Secure Email Gateway processes inbound and outbound email traffic as part of normal operation. According to Cisco[1], exploitation does not require authentication or access to an administrative interface. An attacker can reportedly trigger the vulnerability through malicious email content processed by the gateway.

Cisco has stated that it became aware of active exploitation in September 2026, indicating that the vulnerability was exploited prior to public disclosure. [1]

CVE

CVE-2026-76461

Affected Products

Cisco Secure Email Gateway (Cisco AsyncOS Software) versions[1]:
15.5 and earlier
16.0
16.5

Exploitation

Cisco confirms active exploitation during September 2026[1].
The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.

Recommended Actions

Truesec recommends that you upgrade to one of the fixed versions below.
The vulnerability is fixed in Cisco Secure Email Gateway (Cisco AsyncOS Software) versions[1]:
15.5.5-014
16.0.4-302
16.5.0-780
Detection

To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device. The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs[1]:

cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]

The presence of any entry in the output may indicate malicious activity[1].

References

[1] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights