Cisco Secure Email Gateway is the inspection layer many organisations put in front of Microsoft 365, Google Workspace, Exchange, and other mail systems. Running Cisco AsyncOS as a physical appliance, VM, cloud service, or hybrid deployment, it examines mail before delivery for phishing, spam, malicious content, data-loss-prevention rules, and encryption policy. That inline position is what makes CVE-2026-76461 especially consequential: the attack input is an email message, not an administrator’s browser session.
Cisco’s advisory describes SQL injection in AsyncOS email-parsing logic. The parser does not adequately validate data from a crafted message before it reaches SQL handling. An unauthenticated remote attacker can send an email containing malicious SQL through an affected gateway, execute arbitrary SQL statements, and use that path to run operating-system commands as root. No account, prior foothold, or user interaction is required.
A mail-flow bug becomes appliance control
This is not simply a way to tamper with a message record. Root privileges mean the attacker can control the operating system beneath the gateway: steal configuration or credentials available there, alter filtering behaviour, establish persistence, or use the appliance as a pivot point. The advisory does not publicly identify victims, an attacker, a campaign, malware, or the scale and start date of compromise.
Cisco says its PSIRT learned of active exploitation during September 2026 and detected malicious activity on some Cisco Secure Email Cloud devices; it contacted affected customers and began remediation and recovery. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on September 14, 2026, with a September 17 remediation due date and required forensic triage. CISA lists ransomware use as unknown, so teams should not turn active exploitation into an unsupported ransomware attribution.
No credible public proof of concept or working exploit had surfaced as of September 15. A repository presented by one automated tracker as a PoC is a generic “Draft or TODO” template, not vulnerability-specific exploit code. That does not reduce the urgency: confirmed exploitation can rely on private tooling.
Upgrade, then investigate for root-level activity
Cisco provides fixes, with first fixed releases of 15.5.5-014 for AsyncOS 15.5 and earlier, 16.0.4-302 for the 16.0 branch, and 16.5.0-780 for 16.5. Cisco strongly recommends moving to 16.5.0-780; all earlier builds in those branches should be regarded as affected. Cisco says its cloud devices were already upgraded to that release when it published the advisory. Physical and virtual gateways are affected regardless of configuration, while Secure Email and Web Manager and Secure Web Appliance are not affected by this flaw.
There is no workaround. Inventory every gateway and virtual deployment, schedule the applicable fixed build immediately, and treat externally reachable or mail-receiving systems as first priority. Cisco recommends reviewing mail_logs for suspicious SQL, particularly PostgreSQL COPY ... TO PROGRAM activity, then checking firewall and network logs as well. A root-level intruder may have deleted or hidden local evidence, so a clean appliance log is not a clean bill of health.
The most exposed organisations are those that use a centrally managed email-security gateway across large or distributed mail estates, including enterprises and government environments. Patch first, preserve and investigate evidence in parallel, and use SecAlerts to monitor the actual software stack for new vulnerabilities affecting the products it runs.




