1. Basic Information
- Original Title: CISA Adds Cisco Secure Email Gateway CVE-2026-76461 to KEV
- Source: CISA, Cisco
- Published Date: 2026-09-14
- Updated Date: None
- Severity: Critical
- Severity Rationale: Actively exploited pre-authentication vulnerability leading to root-level command execution on the underlying OS, triggered via incoming email.
- Original Link: CISA Adds Cisco Secure Email Gateway CVE-2026-76461 to KEV
- Related Sources: CISA Known Exploited Vulnerabilities Catalog, Cisco Secure Email Gateway SQL Injection Vulnerability, Cisco CVE Record: CVE-2026-76461
- Related CVE: CVE-2026-76461
- Affected Products: Cisco Secure Email Gateway, Cisco AsyncOS
2. Executive Summary
CISA has added a pre-authentication SQL injection vulnerability in Cisco Secure Email Gateway to the KEV catalog. The vulnerability allows root-level command execution via a specially crafted email, and the remediation deadline for U.S. federal agencies is September 17, 2026. Cisco strongly recommends upgrading to AsyncOS 16.5.0-780.
3. Attack Flow
1. Command execution via crafted email, based on Cisco's description
- An attacker sends a crafted email containing malicious SQL statements to the target appliance.
- Inadequate validation during email parsing results in a SQL injection.
- Successful exploitation leads to arbitrary command execution with root privileges on the underlying OS, according to Cisco.
- Inference: Post-exploitation activity may involve configuration changes, credential harvesting, or external communication. Subsequent actions for specific incidents have not been publicly disclosed.
4. Attacker Position and Execution Location
- An unauthenticated external attacker capable of delivering emails to the Cisco Secure Email Gateway.
5. Visibility for Victims and Administrators
Victim
- The attack occurs during email reception processing and requires no user interaction.
Administrator
- Cisco recommends investigating suspicious SQL statements in
mail_logsas potential indicators of exploitation. Even if no matching records are found, administrators should cross-reference external logs, keeping in mind the possibility of evidence deletion or concealment. - Inference: Check for unusual command execution, configuration changes, or outbound communications following email processing. These are internal investigation perspectives and are distinct from publicly reported incident timelines.
6. Conditions for Success and Failure
Conditions for Success
- A Secure Email Gateway running a vulnerable version of Cisco AsyncOS processes a crafted email. Physical or virtual deployment type and specific enabled features are irrelevant, and no user interaction is required.
Conditions for Failure and Risk Mitigation
- The initial fixed versions are 15.5.5-014 for AsyncOS 15.5 and earlier, 16.0.4-302 for version 16.0, and 16.5.0-780 for version 16.5. Cisco strongly recommends upgrading to 16.5.0-780, which requires an appliance reboot.
- There are no workarounds to resolve this vulnerability. Restricting access to the management interface or separating mail and management networks are defense-in-depth measures and do not replace applying the update.
- If a compromise is suspected, preserve evidence and follow Cisco's recovery procedures based on the appliance deployment type. Applying the update alone does not confirm the resolution of an existing compromise.
- All instances of Cisco Secure Email Cloud have already been updated to 16.5.0-780. Customers contacted by Cisco regarding a potential compromise should rotate credentials, keys, and certificates following the provided guidance.
7. Impact of Successful Exploitation
- Arbitrary commands may be executed with root privileges on the underlying OS.
- Inference: This could lead to the compromise of email data, credentials, and gateway configurations, or the appliance being used as a pivot point for internal lateral movement.
8. Observable Logs
This section covers investigation targets provided by Cisco as well as internal investigation perspectives. Inferences are marked accordingly.
- Cisco identifies
mail_logsas a primary investigation target. Search for suspicious SQL statements, such as case-insensitive patterns likeCOPY.*TO PROGRAM. In a cluster environment, check all member appliances. This search is not exhaustive, and a match alone does not confirm command execution. - Inference: Use the timestamp and message ID of matching records to correlate email processing, appliance activity, and external communication logs.
Proxy, SWG, and DNS
- Inference: If DNS queries or outbound traffic logs from the SEG are available, check for destinations differing from normal email delivery and updates. These are post-compromise investigation perspectives.
Endpoint and EDR
- Inference: Review diagnostic and audit information available on the appliance for command execution or file modifications following email processing. Do not assume standard endpoint EDR tooling is available.
Authentication and IdP
- Inference: Review administrator logins and configuration changes. Because this is a pre-authentication exploit, the absence of administrator login records does not prove the absence of compromise.
SaaS and Cloud
- For Cisco Secure Email Cloud, administrators without CLI access may not be able to independently verify the aforementioned artifacts. Verify investigation and recovery status through Cisco notifications and support.
- Inference: If audit logs for integrated email and authentication services are available, inspect for anomalous operations utilizing SEG credentials.
Network
- Cisco recommends correlating logs with external network and firewall logs. Check for unexpected uploads from affected appliances to external IP addresses or downloads from malicious IP addresses.
- Inference: Correlate email delivery to the SEG with outbound connections by timestamp. Network traffic flows alone do not prove SQL injection or command execution.
9. Determining Attack Success
Confirmable via Public Information
CISA added CVE-2026-76461 to the KEV catalog on September 14, 2026, setting the remediation deadline to September 17 and designating it as requiring forensic investigation. This deadline is an operational requirement for U.S. federal agencies.
Cisco stated that it became aware of active exploitation in September 2026. The CVSS v3.1 score is 9.8, and neither credentials nor user interaction are required.
Internal Evaluation Criteria
-
Confirmed Malware Execution or Successful Authentication: Criteria: Unauthorized command execution related to email processing is corroborated by process or audit logs. A match in
mail_logssearches alone does not confirm successful execution. While Cisco and CISA have confirmed active exploitation, records of root-level execution for specific incidents have not been publicly disclosed. - Confirmed Subsequent Compromise: Criteria: Unauthorized persistence, configuration tampering, credential theft, or compromise of internal systems following initial execution is individually corroborated. Mere creation of new processes or internal connections is insufficient for confirmation, and subsequent actions are unconfirmed in public information.
10. Investigation Playbook
Inference: The following is an internal investigation procedure based on public information.
Starting Point of Investigation
- Verify whether the SEG in use falls under Cisco's affected products list and initiate an investigation alongside checks for anomalies in email processing and appliance behavior.
Initial Verification
- Confirm the deployment type (physical, virtual, or cloud) and the AsyncOS version. Physical and virtual SEGs running vulnerable versions are affected regardless of configuration; do not rule out appliances simply because certain features are disabled.
- Preserve investigation logs before performing updates or reboots. Rebuilding or replacing virtual machines can result in the loss of configurations and logs, so preserve evidence prior to re-provisioning. Review email delivery paths and the exposure scope of management interfaces separately.
Endpoints and Servers
- Inspect
mail_logsacross all cluster appliances for suspicious SQL statements, utilizing search patterns such asCOPY.*TO PROGRAM. Verify command execution and file or configuration modifications at the corresponding timestamps using diagnostic and investigation methods recommended by Cisco.
Authentication and Cloud
- Review administrative operations and credential usage for integrated services to check for unauthorized configuration changes or credential exposure. For Cisco Secure Email Cloud, coordinate with Cisco notifications and support, keeping in mind the limitations of CLI access.
Subsequent Operations
- Check for new outbound communications from the SEG, unauthorized access to internal services, changes to email configurations, or mechanisms of persistence.
Containment
- Update unaffected appliances to a patched version. Cisco strongly recommends migrating to version 16.5.0-780.
- For suspected compromises on on-premises physical appliances, consult Cisco TAC to proceed with investigation and recovery.
- For suspected compromises on on-premises virtual appliances, preserve evidence, deploy a new VM with the patched version, rebuild the configuration, rotate credentials and appliance keys/certificates, and continuously monitor for anomalies. If recovery is difficult, consult Cisco TAC.
- If contacted regarding a potential compromise in Cisco Secure Email Cloud, verify recovery actions taken by Cisco and proceed with rotating credentials, keys, and certificates as guided.
Classification of Findings
- Distinguish between malicious email processing, vulnerability exploitation, command execution, and persistence, data exfiltration, or lateral movement. Do not determine internal compromise status based solely on KEV listing.
11. Defense and Detection Ideas
Inference: The following are proposed detection and mitigation strategies based on public information.
Single Event
- Treat suspicious SQL statements in
mail_logsas detection candidates, utilizing Cisco's search exampleCOPY.*TO PROGRAM. A match serves as a starting point to investigate exploit attempts and must be distinguished from proof of successful execution.
Timeline Correlation
- Correlate the processing timestamp of suspicious emails with appliance execution logs, configuration changes, and outbound connections, distinguishing them from normal maintenance or email delivery.
Threat Hunting
- Inspect mail logs across all cluster appliances active during the vulnerable window and cross-reference them with external traffic and firewall logs. Do not limit the timeframe solely to September, when Cisco became aware of active exploitation.
Log Deficiencies and Limitations
- Because root privileges allow for the deletion and concealment of evidence, the absence of internal logs or search matches does not prove the absence of a compromise. If external logs are also insufficient, the entry vector and success phase may remain unconfirmed.
Priority Mitigations
- Prioritize migration to version 16.5.0-780, strongly recommended by Cisco, along with forensic investigation. There are no alternative workarounds. Combine this with restricting management traffic, separating mail and management networks, and forwarding logs externally, and recover appliances according to their deployment type if compromise is suspected.
12. Facts / Inference / Hypothesis
Facts
- CISA added CVE-2026-76461 to the KEV catalog on September 14, 2026, setting the remediation deadline to September 17 and designating it as requiring forensic investigation. This deadline is an operational requirement for U.S. federal agencies.
- CVE-2026-76461 is a SQL injection vulnerability (CWE-89) in AsyncOS for Cisco Secure Email Gateway.
- According to Cisco, an unauthenticated external attacker can send a crafted email leading to arbitrary command execution with root privileges on the underlying OS.
- Cisco stated that it became aware of active exploitation in September 2026. The CVSS v3.1 score is 9.8, and neither credentials nor user interaction are required.
- Ransomware association is listed as Unknown in the CISA KEV catalog.
- Public information does not disclose the attacker's identity, the number of victims, payloads used during active exploitation, or post-compromise activities.
- Physical and virtual Cisco Secure Email Gateway appliances are affected regardless of configuration if running a vulnerable version. Cisco Secure Email and Web Manager and Secure Web Appliance are not affected by this vulnerability.
- The initial fixed versions by series are 15.5.5-014 for AsyncOS 15.5 and earlier, 16.0.4-302 for version 16.0, and 16.5.0-780 for version 16.5. Cisco strongly recommends upgrading to 16.5.0-780, which triggers an appliance reboot.
- There are no workarounds to resolve this vulnerability. Cisco states that all Cisco Secure Email Cloud instances have been updated to 16.5.0-780.
- To investigate exploit attempts, Cisco advises checking for suspicious SQL statements in
mail_logs, citing case-insensitive searches forCOPY.*TO PROGRAMas an example. For cluster configurations, check logs across all member appliances. A match indicates potential malicious activity but does not confirm successful execution. - Because an attacker with root privileges can delete and conceal evidence, Cisco also recommends cross-referencing external network and firewall logs.
- Cisco recommends consulting Cisco TAC for suspected compromises on on-premises physical appliances, and preserving evidence, rebuilding with a new patched VM, and rotating credentials and appliance keys/certificates for virtual appliances. Customers contacted regarding potential compromises in Cisco Secure Email Cloud are also recommended to rotate credentials, keys, and certificates.
Inference
- On perimeter email gateways receiving mail from the internet, the attack surface for email parsing remains accessible even if the management interface is not publicly exposed.
- Following root-level execution, attackers may proceed to credential theft, email monitoring, or persistence.
Hypothesis
No additional hypotheses. Unconfirmed items are listed under "Unknowns and Additional Investigation."
13. MITRE ATT&CK Mapping
- T1190 Exploit Public-Facing Application (Confidence: High): Exploiting SEG vulnerabilities via externally delivered crafted emails.
- T1059.004 Command and Scripting Interpreter: Unix Shell (Confidence: Low): Candidate technique, as the specific interpreter for root-level command execution has not been publicly disclosed.
14. Unknowns and Additional Investigation
- The attacker's identity, the number of victims, and the exact date when active exploitation began.
- The full scope of emails and payloads used during active exploitation, as well as details regarding command execution, persistence, and information gathering per targeted organization.
15. Impact on SOCs and Organizations
Because processing crafted emails serves as the entry vector, focusing solely on the exposure status of the management interface will cause organizations to overlook the attack surface. Organizations operating SEGs must concurrently pursue migration to Cisco's strongly recommended version 16.5.0-780 and conduct compromise investigations. Since internal evidence may be deleted, mail logs from all cluster appliances should be cross-referenced with external traffic records. If a compromise is suspected, recovery must align with the deployment type, such as consulting Cisco TAC for physical appliances or rebuilding after evidence preservation for virtual appliances.
16. Summary by Role
- SOC: Inspect
mail_logsacross all cluster appliances for suspicious SQL statements and cross-reference with external traffic records. Distinguish between search matches and successful execution, and account for potential evidence deletion or concealment even when no traces are found. - Administrator: Upgrading to AsyncOS 16.5.0-780 is strongly recommended by Cisco. There are no workarounds; if compromise is suspected, preserve evidence, perform recovery tailored to physical, virtual, or cloud deployments, and rotate credentials and keys.
- User: No user interaction is required. Not opening a suspicious email does not guarantee safety on its own.
Top comments (0)