News

Cisco Patches Secure Email Gateway Zero-Day Under Attack

Cisco advisory cisco-sa-esa-inj-2bLVGmhX, first published 14 September 2026, covers CVE-2026-76461 (CVSS 9.8) in Secure Email Gateway AsyncOS. Fixed builds are 15.5.5-014, 16.0.4-302, and 16.5.0-780. CISA KEV is due September 17.

Cisco Patches Secure Email Gateway Zero-Day Under Attack

Cisco's security advisory cisco-sa-esa-inj-2bLVGmhX, first published 14 September 2026, says an email-parsing flaw in AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker run arbitrary commands as root. The hole is CVE-2026-76461, scored CVSS 9.8.

This is a Cisco Product Security Incident Response Team security advisory, plus a CISA Known Exploited Vulnerabilities listing reported by SecurityWeek (Eduard Kovacs, 15 September 2026). It is an actively exploited advisory, not a research proof of concept and not a ransomware incident write-up.

The path is a crafted email that carries malicious SQL statements through an affected device. Physical and virtual Secure Email Gateway appliances are in scope in any configuration. Secure Email and Web Manager and Secure Web Appliance are not.

There are no workarounds. The fixed AsyncOS builds are 15.5.5-014 for 15.5 and earlier, 16.0.4-302 for 16.0, and 16.5.0-780 for 16.5. Cisco strongly recommends migrating to 16.5.0-780. Cisco has already upgraded all Secure Email Cloud devices to that build.

Cisco PSIRT became aware of exploitation in September 2026 and has not named an attacker. To look for attempted exploitation, review mail_logs for suspicious SQL, including the example pattern COPY.*TO PROGRAM. Root access can wipe those indicators, so an empty grep is not proof a box is clean. Cross-check network and firewall logs off the appliance.

CISA added CVE-2026-76461 to KEV on Monday. Federal agencies are due by September 17. This is only the second Cisco Secure Email Gateway vulnerability in KEV, after CVE-2025-20393, which China-linked actors started exploiting in late 2025.

SecurityWeek also notes CVE-2026-76461 is one of several flaws Cisco found internally in Secure Email Gateway and Secure Email and Web Manager. Related enterprise patch urgency includes Microsoft's passkey-themed Microsoft 365 cloud theft and GitLab's max-severity commits API file-read.

If you run on-prem Cisco Secure Email Gateway, physical or virtual, upgrade to 15.5.5-014, 16.0.4-302, or preferably 16.5.0-780 now, treat any unpatched appliance as potentially root-compromised, and meet the September 17 KEV deadline if you are in federal scope.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free