Executive Summary
Cisco has issued a critical advisory regarding CVE-2026-76461, a vulnerability in the AsyncOS email parsing logic for Cisco Secure Email Gateway. This flaw allows a remote, unauthenticated attacker to execute arbitrary SQL statements via crafted emails, leading to full root access on the underlying operating system. The vulnerability has been observed under active exploitation in the wild, leading CISA to add it to the Known Exploited Vulnerabilities (KEV) catalog.
Technically, the attack involves insufficient validation of email content that is subsequently processed by the device's internal database. Attackers can leverage specific SQL commands to escape the database context and execute system-level commands. Because root-level access is achieved, adversaries can potentially delete or hide logs and other indicators of compromise directly on the device, complicating forensic efforts.
This is a high-priority threat for organizations utilizing Cisco Secure Email Gateway. The impact of a successful breach includes total device takeover, potential data theft, and a foothold for further lateral movement. Affected organizations are urged to patch immediately, as there are no known workarounds for this vulnerability.
Key Details
Threat Name
CVE-2026-76461
Affects
Cisco Secure Email Gateway, AsyncOS Software for Cisco Secure Email Gateway, Cisco AsyncOS for Cisco Secure Email Gateway 15.5 and earlier, Cisco AsyncOS for Cisco Secure Email Gateway 16.0, Cisco AsyncOS for Cisco Secure Email Gateway 16.5
Adversary
—
Malware/Tools
None identified
