Cisco has released fixes for a critical Cisco Secure Email Gateway vulnerability that the company says has been actively exploited in the wild.
The flaw, tracked as CVE-2026-76461, was disclosed on September 14, 2026, and carries a CVSS score of 9.8. Cisco describes it as a SQL injection vulnerability in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway.
According to Cisco, an unauthenticated remote attacker could exploit the vulnerability by sending a crafted email message containing malicious SQL statements through an affected device. A successful attack could lead to command execution with root privileges on the underlying operating system.
The issue puts the email gateway itself in the attack path
The business risk is higher than a typical application bug because Secure Email Gateway sits directly in the flow of inbound and outbound email. It is designed to inspect untrusted messages before they reach users, which makes email parsing a high-value attack surface.
Cisco’s advisory lists the attack as requiring no authentication and no user interaction. That means the risk is not limited to stolen credentials or a user clicking a malicious attachment. The vulnerable component is part of how the gateway processes email traffic.
Root-level command execution is also significant. If an attacker reaches that level of access on a security appliance, incident response teams may need to treat the device as potentially compromised infrastructure, not just as a system waiting for a patch.
Affected products and fixed releases
Cisco says CVE-2026-76461 affects physical and virtual Cisco Secure Email Gateway appliances, regardless of device configuration. For this specific vulnerability, Cisco says Secure Email and Web Manager and Secure Web Appliance are not affected.
There are no workarounds for CVE-2026-76461. Cisco says affected customers should upgrade to a fixed software release.
| Software release | First fixed release |
|---|---|
| Cisco AsyncOS for Cisco Secure Email Gateway 15.5 and earlier | 15.5.5-014 |
| Cisco AsyncOS for Cisco Secure Email Gateway 16.0 | 16.0.4-302 |
| Cisco AsyncOS for Cisco Secure Email Gateway 16.5 | 16.5.0-780 |
Cisco says it strongly recommends migration to Release 16.5.0-780. The company also says it has already upgraded all Cisco Secure Email Cloud devices to Release 16.5.0-780.
Active exploitation has been confirmed
Cisco says its Product Security Incident Response Team became aware of active exploitation in September 2026. The company says the vulnerability was found during the resolution of a Cisco Technical Assistance Center support case.
The Canadian Centre for Cyber Security published an advisory on September 14, 2026, listing affected Cisco versions and noting Cisco’s statement that CVE-2026-76461 is being actively exploited. The Canadian advisory also says the U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities database the same day.
CyberScoop reported on September 15 that Cisco did not describe the attackers’ origins, motivations, or the full scope of affected customers in its public advisory. That distinction matters: the confirmed fact is active exploitation, while the scale and attribution of the campaign remain unclear publicly.
Administrators should check for compromise, not just patch
Cisco’s guidance goes beyond applying the fixed release. The company says administrators can review mail_logs for suspicious SQL statements, including searches for COPY.*TO PROGRAM. Cisco describes that example as non-exhaustive.
Cisco also warns that attackers who obtain root privileges may remove or hide evidence of exploitation. For that reason, the company recommends checking network and firewall logs outside the impacted device for suspicious activity, including unexpected uploads from the affected device to external IP addresses or downloads from malicious IP addresses.
For clustered deployments, Cisco says logs should be reviewed on each cluster device. For Cisco Secure Email Cloud, the company says administrators without CLI access may not be able to independently check the indicators described in the advisory. Cisco says it has directly contacted cloud customers whose devices showed malicious activity.
Response guidance differs by deployment type
For suspected exploitation on a physical appliance, Cisco recommends contacting Cisco TAC for support. For suspected exploitation on a virtual appliance, Cisco recommends preserving forensic information before taking recovery steps, because deploying a new instance can destroy configurations and logs.
Cisco’s virtual appliance recovery guidance includes deploying a new virtual machine on a fixed software release, rebuilding the product configuration, renewing credentials and cryptographic materials installed on the appliance, and continuing to monitor for anomalous behavior.
General hardening recommendations from Cisco include preventing direct internet access to the appliance where possible, restricting required access to known trusted hosts, separating mail and management functions onto different network interfaces, sending logs to an external server, disabling unnecessary services such as HTTP and FTP, and using strong authentication methods.
This is an urgent security appliance patch
CVE-2026-76461 combines several high-risk factors: confirmed exploitation, no authentication requirement, no user interaction requirement, no workaround, and possible root-level command execution on an email security product.
For organizations running Cisco Secure Email Gateway, the safest reading of Cisco’s advisory is that patching should be paired with investigation. A fixed release can close the vulnerability going forward, but Cisco’s own warning about root-level access means local evidence may not be complete or reliable after compromise.
Security teams should prioritize fixed software, review Cisco’s indicators and recovery guidance, preserve relevant logs, and escalate suspected compromise through Cisco TAC or an incident response provider.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us






