CISCO has confirmed active exploitation of CVE-2026-76461, a critical SQL injection flaw in the email-parsing logic of AsyncOS Software for Cisco Secure Email Gateway. Rated CVSS 9.8 and classified as CWE-89, the vulnerability can be exploited remotely without authentication or user interaction by sending a specially crafted email containing malicious SQL statements. Successful exploitation may allow arbitrary SQL execution and ultimately operating-system command execution with root privileges.
Cisco became aware of exploitation in September 2026 while handling a TAC support case, and CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 14 September 2026.
The flaw affects physical and virtual Secure Email Gateway appliances regardless of configuration. Cisco lists the first fixed releases as AsyncOS 15.5.5-014 for version 15.5 and earlier, 16.0.4-302 for version 16.0, and 16.5.0-780 for version 16.5. Secure Email and Web Manager and Secure Web Appliance are not affected, and Cisco says there is no workaround.
Administrators should patch promptly, then review `mail_logs` on every appliance and cluster node for suspicious SQL activity, including `COPY…TO PROGRAM` entries, and check external firewall and network telemetry for unexpected connections. Snort rules 67109 and 67110 are available. Suspected compromises should be treated as incidents; Cisco recommends contacting TAC for physical appliances and preserving forensic data before redeploying virtual ones.