Cisco Secure Email Gateway CVE-2026-76461: Unauth SQL Injection to Root — KEV Due Wednesday

By George Bailey   Published: 09/14/26   Updated: 09/14/26   3 min read

Your spam filter just became the crown jewels. Cisco’s Secure Email Gateway has a critical SQL injection bug that lets a crafted message run as root on the appliance — and CISA wants federal agencies patched by Wednesday.

If mail still flows through an on-prem or virtual ESA, this is a same-day triage, not a “queue for the next change window.”

What happened

On September 14, 2026, Cisco disclosed an unauthenticated SQL injection in how AsyncOS parses email. An attacker who can deliver a malicious message can escalate that SQL into root command execution on the underlying OS. Cisco says there are no workarounds.

CISA added the bug to the Known Exploited Vulnerabilities catalog the same day, with a federal due date of September 17, 2026 and forensic triage required under BOD 26-04. Cisco also shipped a broader September hardening release for AsyncOS; this injection is one of the issues in that set.

Why it matters

Email gateways see every inbound message and often hold quarantine, policy, and credentials. Root on that box is full compromise of a perimeter chokepoint — not a spam-filter glitch.

Cisco became aware of active exploitation in September 2026. Root also means attackers can wipe local logs, so external firewall and proxy records matter as much as mail_logs.

What to do first

Details

TrainFirst fixed release
15.5 and earlier15.5.5-014
16.016.0.4-302
16.516.5.0-780 (Cisco strongly recommends)

Advisory: cisco-sa-esa-inj-2bLVGmhX. Hardening release: cisco-sa-hardening-esa-dfCrfXkm.

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.