Security advisories

Cisco Secure Email Gateway Zero-Day Vulnerability (CVE-2026-76461)

September 15, 2026

3 MINS READ

THE THREAT

On September 14th, 2026, Cisco disclosed a critical zero-day SQL injection vulnerability within the Cisco AsyncOS Software for Cisco Secure Email Gateway, both physical and virtual, regardless of configuration. Tracked as CVE-2026-76461 (CVSS: 9.8), exploitation can allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on impacted devices. Cisco has confirmed that patches are available in versions 15.5.5-014, 16.0.4-302, and 16.5.0-780 to address the flaw.

As Cisco has confirmed that they are "aware of active exploitation" of CVE-2026-76461, impacted organizations should ensure that the relevant patches are applied immediately.

What we're doing about it

What you should do about it

Additional information

Exploitation of CVE-2026-76461 does not require any user interaction and involves threat actors sending specially crafted email messages that contain malicious SQL statements through an affected device, due to insufficient validation in the email parsing logic. Successful exploitation can lead to an attacker executing arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system. Guidance is provided within the advisory on searching relevant logs for possible signs of compromise. The advisory notes that for customers of Cisco Secure Email Cloud, the latest updates have already been applied. Cisco also conducted a "thorough threat intelligence investigation" for Cisco Secure Email Cloud customers and directly contacted those where "indicators of possible compromise" were identified.

Although Cisco stated that they are aware of in-the-wild exploitation of the vulnerability, no specific details on attacks were shared. On September 14th, CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog, giving a deadline of September 17th for Federal Civilian Executive Branch (FCEB) agencies to apply relevant patches. As exploitation is ongoing, organizations utilizing Cisco Secure Email Gateway within their environment should apply the relevant patches as soon as possible.

Impacted Product List
Product Vulnerable Version First Fixed Release
Cisco AsyncOS for Cisco Secure Email Gateway Software Release 15.5 and earlier 15.5.5-014
16.0 16.0.4-302
16.5 16.5.0-780

References:
[1] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
[2] https://nvd.nist.gov/vuln/detail/cve-2026-76461
[3] https://www.cisco.com/c/en/us/td/docs/security/security_management/sma/sma16-5/user_guide/b_sma_admin_guide_16_5.html
[4] https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories