Vulnerability record · CVE-2026-76461 · published 14 September 2026
CVE-2026-76461: Cisco AsyncOS email parsing SQL injection allows root command execution
Cisco · Asyncos
Cisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing malicious SQL statements to be injected into backend queries. Because the flaw is reachable without authentication and leads to command execution as root, it is a severe pre-auth remote code execution risk on internet-facing email gateways.
Description
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityPre-auth network-reachable SQL injection leading to root command execution on an internet-facing email gateway, with confirmed KEV listing and a three-day federal remediation deadline.
What it is
Cisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing malicious SQL statements to be injected into backend queries. Because the flaw is reachable without authentication and leads to command execution as root, it is a severe pre-auth remote code execution risk on internet-facing email gateways.
Impact
An unauthenticated remote attacker can execute arbitrary SQL statements and ultimately run arbitrary commands with root privileges on the underlying operating system, giving full control of the gateway appliance.
Attack surface
The vulnerability is reached over the network by sending a crafted email message to an affected device; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any deployment that accepts inbound mail on a vulnerable AsyncOS build is exposed.
Exploitation
CVE-2026-76461 was added to CISA KEV on 2026-09-14 with a remediation due date of 2026-09-17, indicating known exploitation in the wild. EPSS is 0.02009 (79.9th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Cisco Secure Email Gateway fix from the vendor advisory cisco-sa-esa-inj-2bLVGmhX immediately; this is a KEV-listed issue with a 2026-09-17 due date.
- If patching cannot be completed, follow CISA BOD 26-04 guidance, including applying vendor mitigations or discontinuing use of the product where mitigations are unavailable.
- Restrict or monitor inbound SMTP exposure on Secure Email Gateway appliances and evaluate each asset's internet exposure per BOD 26-04.
- Review Cisco's advisory for any interim configuration hardening or workaround specific to the email parsing path.
- Verify no unauthorized changes or persistence on the appliance OS after suspected exposure, given root-level command execution.
Detection
- Inspect mail gateway and AsyncOS logs for malformed or SQL-like content in message headers, envelope fields, or body parsing paths.
- Alert on unexpected child processes, shell invocations, or outbound connections originating from the Secure Email Gateway appliance.
- Monitor for anomalous database query errors or crashes in email parsing services that could indicate injection attempts.
- Hunt for signs of root-level file or configuration changes on the appliance filesystem outside normal update windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on 14 September 2026 as "Cisco Secure Email Gateway SQL Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 17 September 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461 | US Government Resource |
Track CVE-2026-76461 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-76461), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.