www.rapid7.com 15 Sept 2026, 12:22 UTC

Cisco Email Gateway Zero Day Let Attackers Gain Root Access Remotely

Cisco Email Gateway Zero Day Let Attackers Gain Root Access Remotely
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

RAPID 7 says Cisco Secure Email Gateway is affected by CVE-2026-76461, a critical SQL injection vulnerability in AsyncOS Software. Cisco published its advisory on 14 September 2026, reporting a CVSS v3.1 score of 9.8. The flaw could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges by sending a specially crafted email through a vulnerable appliance; access to the administrative interface is not required.

Cisco’s PSIRT became aware of active exploitation in September, and the vulnerability was added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue on the same day, indicating zero-day exploitation before disclosure. No public proof-of-concept code or threat-actor attribution was available when Rapid7 published its report.

Organisations should urgently install Cisco’s fixed releases rather than wait for their normal patching cycle. Version 15.5 and earlier is fixed in 15.5.5-014, version 16.0 in 16.0.4-302, and version 16.5 in 16.5.0-780. Cisco strongly recommends migrating to 16.5.0-780. Administrators can investigate possible exploitation by reviewing the `mail_logs` on every appliance, including each device in a cluster, for suspicious SQL statements. Cisco’s advisory gives `COPY ... TO PROGRAM` as an example; its presence may indicate malicious activity.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline