What it is
CVE-2026-76461 is an unauthenticated Cisco Secure Email Gateway SQL Injection Vulnerability. A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
Vulnerability report
Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco / Cisco Secure Email · 14.0.0-698
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-76461 is an unauthenticated Cisco Secure Email Gateway SQL Injection Vulnerability. A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Cisco / Cisco Secure Email 14.0.0-698.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic.
An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Cisco Security Advisory
A trusted third party reported exploitation.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Cisco PSIRT CSAF First | 2026-09-14 16:00 UTC |
| Cisco Security Advisory | 2026-09-14 16:19 UTC |
| CISA | 2026-09-14 19:40 UTC |
| CVE | 2026-09-14 19:50 UTC |
| TheHackerNews | 2026-09-15 06:11 UTC |
| CERT Polska | 2026-09-15 11:16 UTC |
| Rapid7 | 2026-09-15 12:22 UTC |
| Qualys ThreatPROTECT | 2026-09-15 13:37 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.2%
Recent mention · TheRegister
Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in
Read full advisoryRecent mention · TheRegister
Cisco email security boxes can be rooted by... an emailTheRegister · 15 Sep 2026
Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in
Recent mention · Qualys ThreatPROTECT
Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)Qualys ThreatPROTECT · 15 Sep 2026
Cisco released a security advisory about a critical-severity vulnerability in Cisco Secure Email Gateway. Tracked as CVE-2026-76461, the vulnerability is being exploited in the wild. Successful exploitation of the vulnerability may allow an attacker to execute arbitrary commands with root privileges on the underlying operating system. Cisco TAC team discovered the vulnerability. CISA acknowledged the … Continue reading "Cisco Secure Email Gateway Vulnerability Exploited in Attacks (CVE-2026-76461)"
Recent mention · Rapid7
CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the WildRapid7 · 15 Sep 2026
OverviewOn September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance.Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and...
Recent mention · CERT Polska
Krytyczna podatność w Cisco Secure Email Gateway - wrzesień 2026CERT Polska · 15 Sep 2026
Zespół CERT Polska informuje o krytycznej podatności w oprogramowaniu Cisco AsyncOS dla urządzeń Cisco Secure Email Gateway.Podatność, oznaczona jako CVE-2026-76461, wynika z niewystarczającej walidacji w logice przetwarzania wiadomości mailowych. Pozwala ona na wstrzyknięcie złośliwych instrukcji SQL poprzez wysłanie spreparowanej wiadomości e-mail, co umożliwia nieuwierzytelnionemu, zdalnemu atakującemu wykonanie dowolnych poleceń w systemie operacyjnym z uprawnieniami root. Podatność jest aktywnie wykorzystywana w przeprowadzanych atakach.Podatność dotyczy urządzeń Cisco Secure Email...
Recent mention · TheHackerNews
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command ExecutionTheHackerNews · 15 Sep 2026
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker
Recent mention · Cisco Security Advisory
Cisco Secure Email Gateway SQL Injection VulnerabilityCisco Security Advisory · 14 Sep 2026
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on...
Timeline
Exploitation attested by an external source
Exploitation attested by an external source
Exploitation attested by an external source
Exploitation attested by an external source
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Exploitation attested by an external source
Vulnerability disclosed publicly
High-confidence, third-party attested exploitation
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-76461
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-76461",
"confidence": "Confirmed",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": 0.02162,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}