Your spam filter just became the crown jewels. Cisco’s Secure Email Gateway has a critical SQL injection bug that lets a crafted message run as root on the appliance — and CISA wants federal agencies patched by Wednesday.
If mail still flows through an on-prem or virtual ESA, this is a same-day triage, not a “queue for the next change window.”
What happened
On September 14, 2026, Cisco disclosed an unauthenticated SQL injection in how AsyncOS parses email. An attacker who can deliver a malicious message can escalate that SQL into root command execution on the underlying OS. Cisco says there are no workarounds.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
CISA added the bug to the Known Exploited Vulnerabilities catalog the same day, with a federal due date of September 17, 2026 and forensic triage required under BOD 26-04. Cisco also shipped a broader September hardening release for AsyncOS; this injection is one of the issues in that set.
Why it matters
Email gateways see every inbound message and often hold quarantine, policy, and credentials. Root on that box is full compromise of a perimeter chokepoint — not a spam-filter glitch.
Cisco became aware of active exploitation in September 2026. Root also means attackers can wipe local logs, so external firewall and proxy records matter as much as mail_logs.
What to do first
- Inventory every on-prem and virtual Secure Email Gateway. Upgrade to a fixed build (prefer 16.5.0-780).
- If you use Cisco Secure Email Cloud, confirm Cisco’s upgrade to 16.5.0-780 already landed.
- Hunt
mail_logsfor suspicious SQL (Cisco cites patterns likeCOPY … TO PROGRAM). Check each cluster member. - Cross-check external firewall/proxy logs for odd uploads from the appliance or downloads to unfamiliar IPs.
- If compromise looks likely on a virtual appliance: preserve forensics before rebuild, deploy a clean fixed image, restore config, and rotate credentials and crypto material. Physical boxes: open a Cisco TAC case with remote access enabled.
- Apply the September hardening guidance — don’t cherry-pick one CVE if you’re still on an affected train.
Details
- CVE: CVE-2026-76461 (CVSS 9.8)
- Product: Cisco AsyncOS for Secure Email Gateway (physical and virtual)
- Not affected: Secure Email and Web Manager; Secure Web Appliance
- KEV: Added 2026-09-14; federal due 2026-09-17; forensic triage under BOD 26-04
- Workarounds: None
| Train | First fixed release |
|---|---|
| 15.5 and earlier | 15.5.5-014 |
| 16.0 | 16.0.4-302 |
| 16.5 | 16.5.0-780 (Cisco strongly recommends) |
Advisory: cisco-sa-esa-inj-2bLVGmhX. Hardening release: cisco-sa-hardening-esa-dfCrfXkm.
Hunt / verify
- Search
mail_logsfor SQL-looking payloads andCOPY … TO PROGRAM-style abuse. - Compare appliance outbound connections against baseline; treat post-root local IoCs as potentially incomplete.
- Confirm installed AsyncOS version matches a fixed build above — not just “updates applied.”
Sources
- Cisco PSIRT: Secure Email Gateway SQL Injection (CVE-2026-76461)
- Cisco: Secure Email Gateway / Email and Web Manager Security Hardening — September 2026
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-76461 (due 2026-09-17)
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.