← Vulnerability feed

Vulnerability record · CVE-2026-76461 · published 14 September 2026

CVE-2026-76461: Cisco AsyncOS email parsing SQL injection allows root command execution

Cisco · Asyncos

Cisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing malicious SQL statements to be injected into backend queries. Because the flaw is reachable without authentication and leads to command execution as root, it is a severe pre-auth remote code execution risk on internet-facing email gateways.

9.8 CVSS 3.1 Critical CISA KEV since 14 Sep 2026 EPSS 28% · top 1.9% CWE-89 · SQL injection
9.8CVSS 3.1 base score
28%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
15 Sep 2026Last modified by NVD

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityPre-auth network-reachable SQL injection leading to root command execution on an internet-facing email gateway, with confirmed KEV listing and a three-day federal remediation deadline.

What it is

Cisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing malicious SQL statements to be injected into backend queries. Because the flaw is reachable without authentication and leads to command execution as root, it is a severe pre-auth remote code execution risk on internet-facing email gateways.

Impact

An unauthenticated remote attacker can execute arbitrary SQL statements and ultimately run arbitrary commands with root privileges on the underlying operating system, giving full control of the gateway appliance.

Attack surface

The vulnerability is reached over the network by sending a crafted email message to an affected device; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any deployment that accepts inbound mail on a vulnerable AsyncOS build is exposed.

Exploitation

CVE-2026-76461 was added to CISA KEV on 2026-09-14 with a remediation due date of 2026-09-17, indicating known exploitation in the wild. EPSS is 0.02009 (79.9th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Cisco Secure Email Gateway fix from the vendor advisory cisco-sa-esa-inj-2bLVGmhX immediately; this is a KEV-listed issue with a 2026-09-17 due date.
  • If patching cannot be completed, follow CISA BOD 26-04 guidance, including applying vendor mitigations or discontinuing use of the product where mitigations are unavailable.
  • Restrict or monitor inbound SMTP exposure on Secure Email Gateway appliances and evaluate each asset's internet exposure per BOD 26-04.
  • Review Cisco's advisory for any interim configuration hardening or workaround specific to the email parsing path.
  • Verify no unauthorized changes or persistence on the appliance OS after suspected exposure, given root-level command execution.

Detection

  • Inspect mail gateway and AsyncOS logs for malformed or SQL-like content in message headers, envelope fields, or body parsing paths.
  • Alert on unexpected child processes, shell invocations, or outbound connections originating from the Secure Email Gateway appliance.
  • Monitor for anomalous database query errors or crashes in email parsing services that could indicate injection attempts.
  • Hunt for signs of root-level file or configuration changes on the appliance filesystem outside normal update windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on 14 September 2026 as "Cisco Secure Email Gateway SQL Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 17 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-76461 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-20393Cisco AsyncOS Spam Quarantine HTTP request validation flaw allows root command executionCisco AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager fails to properly validate HTTP requests in the Spam Quarantine feat…KEVEPSS 32%analysed8.8CVE-2022-20871Cisco asyncos os command injection vulnerabilityA vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance…EPSS 1.9%8.8CVE-2022-20868Cisco asyncos hard-coded credentials vulnerabilityA vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appl…EPSS 0.74%8.8CVE-2021-1359Cisco web security appliance vulnerabilityA vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker…EPSS 1.9%8.8CVE-2019-15956Cisco asyncos improper access control vulnerabilityA vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote…EPSS 0.98%8.6CVE-2019-1947Cisco email security appliance improper input validation vulnerabilityA vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthentica…EPSS 1.9%8.6CVE-2019-1886Cisco asyncos improper input validation vulnerabilityA vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a deni…EPSS 1.3%8.6CVE-2018-15460Cisco asyncos improper input validation vulnerabilityA vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthentic…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2026-76461), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.