Cisco Fixes Critical Secure Email Gateway Flaw, CISA Adds It to KEV Catalog

CVE-2026-76461 in Cisco Secure Email Gateway allows remote command execution with root privileges after a specially crafted email is sent. Cisco released fixes, and CISA added it to the KEV catalog.

CVE-2026-76461 in Cisco Secure Email Gateway is a critical SQL injection vulnerability that attackers are actively exploiting, according to the vendor. On September 14, 2026, Cisco released fixes for the affected AsyncOS versions and warned that no workaround exists for the flaw.

The vulnerability is located in email processing in Cisco AsyncOS for Cisco Secure Email Gateway. An unauthenticated remote attacker can send a specially crafted email message and then execute commands with root privileges on the device’s underlying operating system.

Cisco assigned the flaw the identifier CVE-2026-76461 and a CVSS score of 9.8 out of 10, or Critical severity. On the day the advisory was published, the U.S. agency CISA added it to the Known Exploited Vulnerabilities catalog, which tracks flaws with known exploitation.

CVE-2026-76461 in Cisco: Fixes for Three AsyncOS Branches

According to Cisco, operators of Cisco Secure Email Gateway should deploy the available fixes. The vendor released these versions:

  • 15.5.5-014 for the 15.5 branch and older,
  • 16.0.4-302 for the 16.0 branch,
  • 16.5.0-780 for the 16.5 branch.

Because Cisco states that no workaround exists, organizations should identify the AsyncOS version on their devices and verify that the appropriate fixed version is installed after the update.

Checking for Possible Compromise

Deploying the fix alone does not address any prior intrusion. Cisco recommends reviewing mail_logs files for suspicious SQL commands. It also advises checking external network and firewall logs.

This process is important because an attacker with root access may be able to remove or hide local traces, according to Cisco. External records may therefore provide additional information about device communications that could be related to a compromise.

Cisco said it contacted customers of Cisco Secure Email Cloud for whom it found indicators of possible compromise. However, it has not been confirmed that exploitation affected specific customers outside this group. The vendor also did not disclose technical details about the attackers, the scope of the campaign, the number of affected organizations, or a publicly available exploit.

Why an Email Gateway Is a Sensitive Target

An email security gateway processes messages from untrusted external sources and, within organizations, may handle sensitive email as well as internal network services. The ability to remotely gain root access without logging in therefore poses a risk of disrupting device operations, accessing data, or moving further through the network.

The next step for administrators is to update affected devices and conduct a forensic review of the logs. Further indicators of compromise or information about the scope of exploitation may also emerge if Cisco publishes them.

Sources

Verified and updated: 09/15/2026 06:20

Sharing