securityaffairs.com 15 Sept 2026, 20:46 UTC

CISA Flags Critical Cisco Email Gateway Flaw Exploited in Attacks

CISA Flags Critical Cisco Email Gateway Flaw Exploited in Attacks
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76461, a critical Cisco Secure Email Gateway vulnerability with a CVSS score of 9.8, to its Known Exploited Vulnerabilities (KEV) catalogue. Cisco disclosed the zero-day in September 2026 and confirmed that it is being exploited in the wild.

The flaw affects both physical and virtual Cisco Secure Email Gateway appliances, regardless of their configuration. It is caused by insufficient validation in the email-parsing logic. An unauthenticated remote attacker can send a specially crafted email containing malicious SQL statements, potentially executing arbitrary SQL commands and then arbitrary commands on the underlying operating system with root privileges. Cisco said there is no workaround that addresses the vulnerability.

Cisco advises customers to inspect the `mail_logs` on every device, including each appliance in a cluster, for suspicious SQL statements. Its example detection command searches for `COPY.*TO PROGRAM`; any matching entry may indicate malicious activity. Customers using Secure Email Cloud may not be able to check these indicators themselves, although Cisco said it contacted customers where malicious activity was detected.

Under Binding Operational Directive 22-01, US federal civilian agencies must remediate the flaw by 17 September 2026. CISA also recommends that private organisations review and address the vulnerability where relevant.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline