Skip to content

Security Bulletin 7min read

Unauthenticated Remote Code Execution in Cisco Secure Email Gateway (CVE-2026-76461)

Last update: 15 September, 2026
Tags: Security Bulletin
 Brandon Sawyer
 Brandon Sawyer

Published: Tue 15 September 2026

Prepared by: Brandon Sawyer, Vulnerability Analyst

Purpose

On 14 September 2026, Cisco disclosed a critical, unauthenticated remote code execution vulnerability affecting Cisco Secure Email Gateway (SEG), assigned CVE-2026-76461. The flaw allows a remote, unauthenticated threat actor (TA) to send a specially crafted email to a vulnerable appliance and achieve arbitrary operating system command execution with root privileges. Cisco has stated it became aware of active exploitation in September 2026, and on the same day the US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue, confirming active exploitation. No Australian regulator advisory specific to this CVE has been identified at the time of writing. However, Australian organisations running Secure Email Gateway should nonetheless treat patching as an emergency priority, consistent with the vulnerability's critical severity and confirmed in-the-wild exploitation. 

Vulnerability Details

CVE-2026-76461 is a SQL injection vulnerability (CWE-89) in the email parsing logic of Cisco AsyncOS software, which underpins Cisco Secure Email Gateway. It carries a CVSSv3.1 base score of 9.8 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network-based attack access, low attack complexity, no user interaction, and no privileges required. 

A TA requires no credentials and no user interaction to exploit the flaw. By sending a crafted email message containing malicious SQL statements to an affected appliance, insufficient validation in the email parsing logic allows those statements to be executed, ultimately enabling arbitrary operating system command execution with root-level privileges on the underlying host.

The vulnerability affects Cisco Secure Email Gateway, in both physical and virtual form, regardless of device configuration, across the 15.5-and-earlier, 16.0, and 16.5 release lines. Cisco has confirmed that Cisco Secure Email and Web Manager and Cisco Secure Web Appliance are not affected. The vulnerability was identified during the resolution of a Cisco Technical Assistance Center (TAC) support case rather than through a researcher disclosure programme, and Cisco has indicated that its Product Security Incident Response Team (PSIRT) became aware of active exploitation around the time of disclosure, meaning there was little or no gap between public disclosure and confirmed in-the-wild use.

Cisco has released fixed software for all affected release lines and has not published a workaround; upgrading remains the only remediation path.

Discovery and Disclosure Timeline

Date Event
14 Sept 2026 Cisco publishes initial advisory (cisco-sa-esa-inj-2bLVGmhX); CVE-2026-76461 registered; fixed releases 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 published; Cisco PSIRT states it became aware of active exploitation this month 
14 Sept 2026 CISA adds CVE-2026-76461 to the KEV catalogue, confirming active exploitation 
Ongoing Cisco continues remediation and recovery work on Cisco Secure Email Cloud devices where indicators of possible compromise were identified, and continues to monitor for further exploitation reports 

Impact

Successful exploitation grants a TA remote, unauthenticated code execution at root level on the affected Secure Email Gateway appliance. Because this class of appliance sits at the perimeter of an organisation's email flow and often holds credentials and configuration data for connected mail infrastructure, a compromised device can expose:

  • Root-level control of the appliance operating system, including the ability to install persistence mechanisms or additional tooling
  • Configuration data, quarantine contents, and any credentials or connection details stored on or accessible to the appliance
  • A foothold for lateral movement into connected mail and management infrastructure

Cisco has noted that, because successful exploitation grants root-level access, a TA may be able to remove or hide evidence of exploitation, and has recommended that administrators cross-check network and firewall logs external to the affected device for signs of suspicious activity, including unexpected outbound transfers or connections to known-malicious infrastructure. Cisco has confirmed it has directly contacted Secure Email Cloud customers where indicators of possible compromise were identified, but has not published a count or identity of affected on-premises customers, and has not published specific indicators of the tooling or infrastructure used by a TA.

Mitigation

Primary Remediation

The primary remediation is to upgrade all Cisco Secure Email Gateway appliances to the fixed release for the relevant release line:

Cisco AsyncOS for Secure Email Gateway Release First Fixed Release
15.5 and earlier 15.5.5-0141
16.0 16.0.4-3021
16.5 16.5.0-780

Cisco recommends migrating to 16.5.0-780 where possible. Cisco has stated that no workaround exists for this vulnerability, so upgrading is the only way to close the entry point.

As with any pre-authentication, unauthenticated remote code execution vulnerability, applying the fix closes the entry point but does not remove a TA who may already have gained access. Given Cisco's own acknowledgement that exploitation was already occurring at the time of disclosure, organisations should treat any internet-facing Secure Email Gateway appliance as potentially compromised until logs and other indicators have been reviewed, regardless of how recently the appliance was patched.

Compensating Controls

Cisco has stated that no workarounds address this vulnerability directly. Where an immediate upgrade cannot be completed, the following controls can reduce exposure in the interim, consistent with Cisco's general hardening guidance for this product line:

  • Restrict inbound access to the appliance's management interfaces to trusted networks only, using firewall rules or an access-control gateway
  • Separate mail-handling and management functionality onto distinct network interfaces where the platform supports it
  • Disable unused network services, including HTTP, on the appliance

These measures reduce the appliance's exposed attack surface but do not close the underlying flaw in email parsing, and will not remove any persistence a TA established before the workaround was applied.

Hardening and Longer-Term Actions

Beyond immediate remediation, Cisco recommends placing Secure Email Gateway and Secure Email and Web Manager appliances behind a filtering device such as a firewall, restricting appliance access to known, trusted hosts, and using strong authentication methods such as SAML or LDAP for administrator access rather than local accounts. Organisations that identify or cannot rule out compromise should renew credentials and any cryptographic material stored on or accessible to the appliance, and, for virtual appliances, consider rebuilding from a clean, fixed-release image after preserving forensic evidence.

Detection

Indicators and Log-Based Detection

Cisco has published guidance for identifying potential exploitation attempts in the appliance's mail logs. These indicators should be treated as a starting point rather than a complete picture:

  • Reviewing mail logs for log entries indicating a "COPY...TO PROGRAM" pattern or similar SQL constructs may indicate an attempted or successful exploit and warrant further investigation
  • If the appliance is part of a cluster, logs from every cluster member should be reviewed, since exploitation may not be visible from a single node
  • Because successful exploitation grants root-level access, a TA may be able to remove or alter local log evidence; Cisco recommends cross-checking external network and firewall logs for unexpected outbound connections from the affected device

Recommended Detection and Hunting Activities

  • Review Secure Email Gateway mail logs across all cluster members for the SQL-related indicators above, focusing on the period since the vulnerability's practical existence in supported releases and, in particular, the weeks leading up to the 14 September 2026 disclosure
  • Cross-correlate any suspicious log entries with firewall and network logs external to the appliance
  • Ensure centralised, retained logging is in place for the appliance to support retrospective investigation, given that on-device logs may not be reliable evidence of compromise
  • If any indicator is identified, or patching was delayed, treat the environment as potentially compromised, rotate credentials and cryptographic material accessible to the appliance, and engage incident response
  • Organisations that identify suspected exploitation should contact Cisco TAC directly for assistance, and virtual appliance owners should preserve forensic evidence before rebuilding
This remains an emerging situation, and we urge all organisations running Cisco Secure Email Gateway to stay up to date with information from trusted vendor sources as further guidance is published.

MDR customers: Triskele Labs will continue tuning detections and analysing IOCs for behaviours consistent with the exploitation of CVE-2026-76461 across supported log sources. 

Vulnerability Management customers: Environments will be assessed for vulnerable versions of Cisco Secure Email Gateway affected by CVE-2026-76461 once vulnerability scan detection becomes available. Any findings will be communicated through established priority notification channels.

 


References