CISA has added a critical Cisco Secure Email Gateway vulnerability to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw in real-world attacks.
The issue, tracked as CVE-2026-76461, affects Cisco AsyncOS software used by Cisco Secure Email Gateway appliances. CVE-2026-76461 is an SQL injection vulnerability, categorized under CWE-89.
It could allow an unauthenticated remote attacker to send specially crafted requests to a vulnerable Cisco Secure Email Gateway device and execute arbitrary commands on the underlying operating system.
Successful exploitation may provide root-level privileges, giving an attacker full control of the affected appliance. Cisco Secure Email Gateway is commonly deployed at the edge of enterprise networks to inspect email traffic and block malicious messages, spam, phishing attempts, and malware.
Compromising such a system could create serious security risks because the appliance processes large volumes of inbound and outbound email, including messages containing sensitive business information.
An attacker with root access could potentially alter email security policies, access stored message data, create persistence mechanisms, turn off security logging, or use the compromised gateway as an entry point into the wider network.
Security teams should also investigate whether the appliance has communicated with unfamiliar external infrastructure or shown unexpected administrative activity.
CISA added the vulnerability to the KEV catalog on September 14, 2026, and directed affected federal civilian executive branch agencies to apply vendor-provided mitigations by September 17, 2026.
The agency also marked the issue as requiring forensic triage under Binding Operational Directive 26-04, reflecting the elevated risk associated with confirmed exploitation.
The listing does not confirm whether the vulnerability has been used in ransomware operations. However, vulnerabilities that enable unauthenticated remote command execution with root privileges are highly valuable to threat actors, particularly when the affected product is internet-facing.
Organizations using Cisco Secure Email Gateway should identify all exposed AsyncOS instances, confirm their software versions, and apply Cisco’s recommended mitigation measures as soon as possible.
Where mitigations are unavailable, CISA advises organizations to follow applicable BOD 26-04 guidance for cloud services or discontinue use of the affected product. Security teams should prioritize incident-response checks alongside remediation.
Relevant triage actions include reviewing appliance logs for suspicious requests, checking for unauthorized configuration changes, examining privileged account activity, and looking for unexpected command execution or outbound network connections.
Because the flaw can be exploited remotely without authentication, organizations should treat any unpatched internet-accessible device as potentially compromised.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…