Active Exploitation Alert: Cisco Secure Email Gateway AsyncOS SQL Injection (CVE-2026-76461) Added to CISA KEV — Unauthenticated Root via Crafted Email

Active Exploitation Alert: Cisco Secure Email Gateway AsyncOS SQL Injection (CVE-2026-76461) Added to CISA KEV — Unauthenticated Root via Crafted Email

Executive Summary

CVE-2026-76461 is a critical SQL injection vulnerability (CWE-89) in email parsing logic on Cisco Secure Email Gateway (SEG / formerly IronPort ESA) running Cisco AsyncOS. An unauthenticated remote attacker can send a crafted email containing malicious SQL through an affected device, execute arbitrary SQL, and achieve command execution as root on the underlying operating system. Cisco rates the issue CVSS 3.1 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). There are no workarounds.

Cisco published security advisory cisco-sa-esa-inj-2bLVGmhX on September 14, 2026 (v1.0 Final) and stated PSIRT became aware of active exploitation in September 2026. CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog the same day, with a federal remediation due date of September 17, 2026, forensic triage required = Yes, and known ransomware campaign use = Unknown. NVD status is Analyzed (lastModified September 15, 2026). Rapid7 assesses pre-disclosure (zero-day) exploitation; Rapid7 and Beazley reported no public PoC at their publication dates. No public threat-actor attribution appears in Cisco, CISA, Rapid7, or Beazley coverage reviewed for this advisory.

Fixed AsyncOS releases: 15.5.5-014 (for 15.5 and earlier), 16.0.4-302 (for 16.0), and 16.5.0-780 (for 16.5). Cisco strongly recommends migrating to 16.5.0-780. Cisco Secure Email Cloud devices were already upgraded by Cisco to 16.5.0-780. Cisco Secure Email and Web Manager (SMA) and Cisco Secure Web Appliance (WSA) are confirmed not vulnerable.

Technical Information

Per Cisco, insufficient validation in Secure Email Gateway email parsing allows a crafted message with malicious SQL to be processed into SQL execution and then root OS command execution. Authentication is not required; user interaction is not required. Physical and virtual Secure Email Gateway appliances are affected regardless of device configuration.

Cisco states the vulnerability was identified in the context of a TAC support case. Defensive observables published by Cisco (not an exhaustive IoC package) include reviewing mail_logs for suspicious SQL, with an example detection pattern of COPY.*TO PROGRAM on IronPort text mail logs, checking every cluster member. Cisco lists Snort rules 67109–67110 as a detection aid. Cisco also warns that root access may allow actors to remove or hide on-box evidence, so operators should cross-check external network/firewall logs for unexpected uploads from the device or downloads from malicious IPs.

Primary sources reviewed (Cisco SA, CISA KEV/alert, NVD, Rapid7 ETR, Beazley) do not explicitly map CVE-2026-76461 to MITRE ATT&CK technique IDs. This advisory does not invent ATT&CK mappings or APT attribution.

Affected Product Versions

Vendor: Cisco. Affected product: Cisco Secure Email Gateway (physical and virtual) running Cisco AsyncOS Software — regardless of device configuration (Cisco SA, 2026-09-14).

Fixed software (Cisco SA Fixed Software table — prefer this for remediation):

  • AsyncOS 15.5 and earlier → first fixed release 15.5.5-014 (Cisco strongly recommends migrate to 16.5.0-780)
  • AsyncOS 16.0 → first fixed release 16.0.4-302 (same migration recommendation)
  • AsyncOS 16.5 → first fixed release 16.5.0-780 (preferred fixed target)

NVD CPE framing (Analyzed): AsyncOS versions end excluding 15.5.5-014; 16.0 inclusive to excluding 16.0.4-302; 16.5 inclusive to excluding 16.5.0-780 on Secure Email Gateway hardware/virtual appliance CPEs. Prefer Cisco’s fixed-release table for patch decisions.

Related products:

  • Cisco Secure Email Cloud: Cisco states it already upgraded all Secure Email Cloud devices to 16.5.0-780 and contacted cloud customers where malicious activity was detected.
  • Cisco Secure Email and Web Manager (SMA): confirmed not vulnerable.
  • Cisco Secure Web Appliance (WSA): confirmed not vulnerable.

Workaround and Mitigation

Cisco states there are no workarounds. Remediation is upgrade only.

  1. Inventory every Secure Email Gateway (physical/virtual) and every MSP/hosted Secure Email Cloud path that terminates or inspects mail for your domains.
  2. Upgrade customer-managed AsyncOS to a fixed release: 15.5.5-014, 16.0.4-302, or preferably 16.5.0-780 (GUI System Administration → System Upgrade, or CLI upgrade / DOWNLOADINSTALL).
  3. For Secure Email Cloud: confirm Cisco’s 16.5.0-780 uplift for your tenant and ask whether Cisco notified your account of detected malicious activity.
  4. Because CISA KEV requires forensic triage (Yes) under BOD 26-04 with due date September 17, 2026 for FCEB, do not treat “version bumped” as residual-risk closed without compromise assessment.
  5. Hunt mail_logs for suspicious SQL (Cisco example: COPY.*TO PROGRAM) on every cluster member; enable or validate Snort 67109–67110 or equivalent where applicable; review off-box network logs for unexpected gateway egress/ingress.
  6. If compromise is suspected: physical appliances — contact Cisco TAC (enable remote access as directed); virtual — preserve forensics, redeploy a fixed VM, rebuild configuration, renew credentials and cryptographic materials, and monitor.
  7. Cloud customers contacted by Cisco should still follow Cisco’s guidance on credential/crypto renewal even after the fleet uplift.

Indicators of Compromise

Cisco, CISA, and NVD do not publish a full public IoC package (IP lists, malware hashes, or C2 domains) for CVE-2026-76461 in the sources reviewed.

Honest empty for official network IoC packages: none published as of this pack date.

Cisco does publish on-box investigation guidance: review mail_logs for suspicious SQL; example pattern COPY.*TO PROGRAM on IronPort text mail logs; check every cluster member; consider Snort rules 67109–67110; cross-check external network/firewall logs because root may wipe on-box evidence. Treat these as vendor-sourced investigation leads, not an invented IoC list. Do not invent ATT&CK IDs or additional indicators.

References

Third-Party Risk Bridge: Managed Email Gateways as a Shared Control Plane

Secure Email Gateway sits in the email supply chain for enterprises and managed-email vendors. CVE-2026-76461 does not require admin UI exposure or credentials—any attacker who can deliver mail through a vulnerable SEG can target the appliance itself and reach root. A compromised MSP or hosted Secure Email Cloud / ESA path is therefore a multi-tenant confidentiality and integrity failure: redirect rules, quarantine, crypto materials, and message content on that path are in scope. Cisco already contacted some cloud customers with detected activity; CISA’s KEV listing requires forensic triage (Yes) with a September 17, 2026 federal due date. Ask providers whether your domains were notified, whether off-box logs were hunted (including COPY…TO PROGRAM across cluster members), and whether secrets were renewed—not only whether AsyncOS shows 16.5.0-780.

Book a demo to see how Rescana tracks email-security and MSP vendors for KEV-class gateway RCE, version attestation, and forensic-triage evidence after incidents like this.

Forward this advisory to your TPRM owner if an MSP, CES provider, or partner Secure Email Gateway terminates mail for your domains—they own the AsyncOS build attestation, IoC-notification ask, and post-exploit credential-rotation evidence above.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.