Critical Vulnerability in Cisco Secure Email Gateway Under Active Exploitation (CVE-2026-76461)
Executive Summary
On September 14th, 2026, Cisco disclosed a critical vulnerability in the email parsing logic of AsyncOS Software for Cisco Secure Email Gateway. Tracked as CVE-2026-76461, CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog the same day, confirming exploitation in the wild. Cisco confirms the vulnerability affects both physical and virtual appliances regardless of device configuration
The flaw lets an unauthenticated, remote attacker send a crafted email message containing malicious SQL statements and execute arbitrary commands with root privileges on the underlying operating system. Successful exploitation could give an attacker full control of the mail gateway, exposing sensitive data and providing a trusted foothold inside the network.
Given confirmed in-the-wild exploitation, root-level impact, and the absence of any workaround, Beazley Security recommends affected organizations apply available fixes immediately and conduct a thorough review for any signs of compromise.
Affected Systems and Products
Cisco confirmed this vulnerability does not affect Secure Email and Web Manager, and Secure Web Appliance.
Mitigations and Workarounds
Cisco states there are no workarounds for this vulnerability. Upgrading to a fixed AsyncOS release is the only remediation, and Cisco recommends customers migrate to Release 16.5.0-780 to fix this flaw. See the “Patches” section of this advisory for more information on upgrading.
Patches
Cisco has released fixed AsyncOS software for customer-managed Secure Email Gateway appliances, and details are available in the official Cisco advisory. Cisco has already upgraded all Cisco Secure Email Cloud devices to Release 16.5.0-780.
Administrators can upgrade an affected device through the web-based management interface as follows:
1. Choose System Administration > System Upgrade.
2. Click Upgrade Options, then Download and Install.
3. Choose the target release and set the options in the Upgrade Preparation area.
4. Click Proceed. The device reboots when the upgrade completes.
Administrators can also run `upgrade` from the CLI and enter `DOWNLOADINSTALL`.
If prior exploitation is suspected, patching alone will not fully address the risk. Cisco recommends contacting Cisco TACfor additional guidance and support.
Indicators of Compromise (IOCs)
On September 14th, 2026, CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Cisco states they have directly contacted Secure Email Cloud customers whose devices showed evidence of malicious activity.
Defenders can review the IronPort text mail logs (`mail_logs` by default) for unexpected SQL statements. Cisco provided the following example of how malicious SQL statements could be detected. If the appliance is part of a cluster, defenders should review the logs on every cluster member:
cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]
Because successful exploitation grants root privileges, an attacker can remove or hide artifacts and on-device evidence may be unreliable. Defenders can also cross-check network and firewall logs collected outside the appliance for unexpected outbound uploads from the gateway to external addresses and for downloads from known malicious infrastructure.
Technical Details
The flaw is a SQL injection in the code that parses inbound email. Cisco has not published the specific field or parser involved, but the flaw allows an attacker to craft an email containing SQL syntax, send it through the gateway, and the parsing logic passes that content into a database query without adequate validation. Once the attacker controls SQL execution, they can escalate from database access to operating system command execution as root.
Exploitation requires no authentication or user interaction, and attackers can exploit the appliance through its normal handling and processing of incoming mail. Cisco also confirms the vulnerability exists regardless of device configuration, leaving no configuration-based workaround to reduce exposure while patching.
Cisco confirmed the vulnerability is being actively exploited after identifying it during investigation of a customer support case and the finding indicates the flaw was exploited prior to public disclosure. No public proof-of-concept exploit was known at the time of this writing.
How Beazley Security is Responding
Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.
We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.
If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.
Sources
Aware of an incident impacting your industry? Let us know: