Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-76461

Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco / Cisco Secure Email · 14.0.0-698

Severity
CVSS 9.8 · Critical
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
2.2%
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-76461 is an unauthenticated Cisco Secure Email Gateway SQL Injection Vulnerability. A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Cisco / Cisco Secure Email 14.0.0-698.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

Cisco Secure Email Gateway SQL Injection Vulnerability

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic.

An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Cisco Affected
Cisco Secure Email
14.0.0-698 13.5.1-277 13.0.0-392 14.2.0-620 13.0.5-007 13.5.4-038 14.2.1-020 14.3.0-032 15.0.0-104 15.0.1-030 15.5.0-048 15.5.1-055 15.5.2-018 16.0.0-050 15.0.3-002 16.0.0-054 15.5.3-022 16.0.1-017 15.5.4-012 16.0.4-016 15.0.5-016 16.0.2-112 16.0.3-044
Published
14 Sep 2026
Exploitation Reported
14 Sep 2026
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

edge cisa

CVE References

  • CVE Record CVE.org · CVE Record https://www.cve.org/CVERecord?id=CVE-2026-76461
  • cisco-sa-esa-inj-2bLVGmhX sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Cisco Security Advisory

Recorded 14 Sep 2026

A trusted third party reported exploitation.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
Cisco PSIRT CSAF First 2026-09-14 16:00 UTC
Cisco Security Advisory 2026-09-14 16:19 UTC
CISA 2026-09-14 19:40 UTC
CVE 2026-09-14 19:50 UTC
TheHackerNews 2026-09-15 06:11 UTC
CERT Polska 2026-09-15 11:16 UTC
Rapid7 2026-09-15 12:22 UTC
Qualys ThreatPROTECT 2026-09-15 13:37 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

9.8 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

2.2%

Recent mention · TheRegister

Cisco email security boxes can be rooted by... an email

Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in

Read full advisory

All Mentions

Recent mention · TheRegister

Cisco email security boxes can be rooted by... an email

TheRegister · 15 Sep 2026

Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in

Recent mention · Qualys ThreatPROTECT

Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)

Qualys ThreatPROTECT · 15 Sep 2026

Cisco released a security advisory about a critical-severity vulnerability in Cisco Secure Email Gateway. Tracked as CVE-2026-76461, the vulnerability is being exploited in the wild. Successful exploitation of the vulnerability may allow an attacker to execute arbitrary commands with root privileges on the underlying operating system. Cisco TAC team discovered the vulnerability. CISA acknowledged the … Continue reading "Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)"

Recent mention · Rapid7

CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

Rapid7 · 15 Sep 2026

OverviewOn September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance.Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and...

Recent mention · CERT Polska

Krytyczna podatność w Cisco Secure Email Gateway - wrzesień 2026

CERT Polska · 15 Sep 2026

Zespół CERT Polska informuje o krytycznej podatności w oprogramowaniu Cisco AsyncOS dla urządzeń Cisco Secure Email Gateway.Podatność, oznaczona jako CVE-2026-76461, wynika z niewystarczającej walidacji w logice przetwarzania wiadomości mailowych. Pozwala ona na wstrzyknięcie złośliwych instrukcji SQL poprzez wysłanie spreparowanej wiadomości e-mail, co umożliwia nieuwierzytelnionemu, zdalnemu atakującemu wykonanie dowolnych poleceń w systemie operacyjnym z uprawnieniami root. Podatność jest aktywnie wykorzystywana w przeprowadzanych atakach.Podatność dotyczy urządzeń Cisco Secure Email...

Recent mention · TheHackerNews

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

TheHackerNews · 15 Sep 2026

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

Recent mention · Cisco Security Advisory

Cisco Secure Email Gateway SQL Injection Vulnerability

Cisco Security Advisory · 14 Sep 2026

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on...

Timeline

From disclosure to observed exploitation

  1. KEV confirmed by Qualys ThreatPROTECT

    Exploitation attested by an external source

  2. KEV confirmed by Rapid7

    Exploitation attested by an external source

  3. KEV confirmed by CERT Polska

    Exploitation attested by an external source

  4. KEV confirmed by TheHackerNews

    Exploitation attested by an external source

  5. KEV confirmed by CVE

    Exploitation attested by an external source

  6. Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  7. KEV confirmed by Cisco Security Advisory

    Exploitation attested by an external source

  8. CVE published

    Vulnerability disclosed publicly

  9. Added to Previdian KEV Feed

    High-confidence, third-party attested exploitation

  10. CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-76461

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-76461",
  "confidence": "Confirmed",
  "cvss_score": 9.8,
  "cvss_estimated": false,
  "epss_score": 0.02162,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}