Security Advisory
CVE-2026-76461: CISA Gives Federal Civilian Agencies Three Days to Patch a Cisco Email Gateway Flaw Under Attack
Cisco disclosed a critical-severity, unauthenticated SQL injection flaw in Secure Email Gateway that lets an attacker gain root access with nothing more than a crafted email. CISA confirmed active exploitation the same day.
Cisco published security advisory cisco-sa-esa-inj-2bLVGmhX on September 14, 2026, disclosing CVE-2026-76461, a critical SQL injection vulnerability in Secure Email Gateway that carries a CVSS v3.1 base score of 9.8. In the same advisory, Cisco stated that its Product Security Incident Response Team "became aware of active exploitation of this vulnerability" in September 2026. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog that same day, and set a remediation due date of September 17, 2026, only three days out, for federal civilian agencies under Binding Operational Directive 26-04, according to Cisco's security advisory and CISA's Known Exploited Vulnerabilities catalog.
Secure Email Gateway is the appliance, physical or virtual, that many mid-size and larger organizations put in front of their mail flow to filter spam, malware, and phishing before messages reach an inbox. Cisco's advisory describes the flaw as reachable "regardless of device configuration," meaning every deployment mode is exposed, not only a specific feature combination.
No Credentials, No Clicks, Just a Crafted Email
Cisco's advisory attributes the vulnerability to insufficient validation in the appliance's email parsing logic. An attacker can send a single crafted email containing malicious SQL statements to a vulnerable appliance; because the parsing logic does not sanitize that input properly, the attacker's SQL runs, and Cisco states the result "could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system." No authentication, no user interaction, and no reply from anyone inside the organization is required. The email only has to arrive.
Cisco's advisory lists the vulnerable AsyncOS software releases as 15.5 and earlier, 16.0, and 16.5. Fixed releases are 15.5.5-014, 16.0.4-302, and 16.5.0-780; Cisco's advisory notes that it "strongly recommends that customers migrate to Release 16.5.0-780" regardless of which fixed build a customer lands on. Cisco has published no interim workaround; the only remediation is upgrading to one of those fixed builds.
What to Check Right Now
Confirm your AsyncOS version against Cisco's fixed releases, and treat this as an emergency change rather than something to fold into a routine maintenance window. If your organization outsources email security management to an IT provider or managed service provider, ask directly whether any Secure Email Gateway appliance in your environment has already been patched, and ask for the exact build number rather than a general assurance.
Because a crafted email is the entire attack, and because Cisco has confirmed exploitation is already underway, an unpatched appliance that has been receiving external mail since before September 14 should be treated as a possible compromise, not only a missing patch. Cisco's advisory directs administrators to review mail_logs on each cluster device for suspicious SQL statements, and to cross-reference network and firewall logs for uploads or downloads to unfamiliar external addresses, noting that an attacker who gained root access may also attempt to remove evidence of the intrusion from the device itself. Security researchers tracking internet-exposed systems, cited by BleepingComputer, reported more than 400 Cisco Secure Email Gateway appliances reachable from the public internet, with no visibility into how many have already applied the fix.
What This Means for Your Compliance Obligations
An email security gateway sits directly in the path of the personal and financial information a mail system routes every day, which puts it squarely inside the systems a documented risk assessment is supposed to cover. Under the FTC Safeguards Rule, 16 CFR 314.4(d)(2) requires nonbanking financial institutions to either run continuous monitoring of their information systems or, absent that, conduct annual penetration testing plus vulnerability assessments at least every six months; institutions maintaining customer information on fewer than 5,000 consumers are exempt from that paragraph entirely under 16 CFR 314.6. For healthcare organizations, HHS Office for Civil Rights guidance states plainly that identifying known, actively exploited vulnerabilities in network infrastructure that handles protected health information is part of the HIPAA Security Rule's risk analysis obligation under 45 CFR 164.308(a)(1)(ii)(A), and remediating what that analysis finds falls under the separate risk management obligation in 164.308(a)(1)(ii)(B). CISA's three-day window applies only to federal civilian agencies, but the underlying fact, a critical-severity, unauthenticated, actively exploited flaw with no workaround, is exactly the kind of known risk those obligations already require a business to identify and act on.
If your organization operates a Cisco Secure Email Gateway, or relies on a vendor who does, confirm the patched build today. Cyber One Solutions can help verify your exposure through our IT and security assessments, which inventory internet-facing infrastructure like this one, and our managed cybersecurity service, which keeps email security appliances patched and monitored on a documented schedule.
Sources
- Cisco Security Advisory: Cisco Secure Email Gateway SQL Injection Vulnerability
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-76461
- BleepingComputer: New Cisco Secure Email zero-day exploited to execute commands as root
- Federal Trade Commission: FTC Safeguards Rule, What Your Business Needs to Know
- HHS OCR: January 2026 Cybersecurity Newsletter
