Skip to main content
QUIETLYTIC
Vulnerability

Cisco Secure Email Gateway SQL Injection (CVE-2026-76461)

CVE-2026-76461 is a CVSS 9.8 SQL injection flaw in Cisco Secure Email Gateway's AsyncOS email parsing that allows unauthenticated root command execution.

CVE-2026-76461
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Cisco Secure Email Gateway

CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on September 14, 2026 — the same day NVD published the record. NVD scores it 9.8 (critical), with a vector describing a network-reachable flaw that needs no privileges and no user interaction, and rates confidentiality, integrity, and availability impact high across the board.

What the flaw is

NVD and both KEV feeds classify CVE-2026-76461 as CWE-89 (SQL injection), and that classification is the single best-corroborated fact in the record: NVD, CISA’s KEV entry, and VulnCheck’s KEV feed all assign the same CWE independently. Per NVD, the defect sits in the email-parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway, where validation of message content is insufficient — SQL statements carried in an inbound message reach the appliance’s database layer as instructions rather than inert text. NVD’s record carries the consequence further than data access: the arbitrary SQL execution ends in commands running as root on the host operating system beneath the appliance.

The delivery channel is what separates this from an ordinary injection bug. A secure email gateway exists to accept unauthenticated input from arbitrary senders; that is its job description, not a misconfiguration. There is no session to hijack and no credential to phish first, and the CVSS vector reflects exactly that (PR:N, UI:N).

Worth reading precisely: the vector records scope as unchanged (S:U), so the blast radius NVD describes is confined to the appliance itself rather than crossing a trust boundary into the wider network. That is a narrower technical claim than the impact suggests, because the appliance in question handles an organisation’s entire inbound and outbound mail flow. Root on that host is root on the mail path.

Why it reached KEV on the day of disclosure

CISA lists a CVE only once it holds evidence of real-world exploitation, so a same-day KEV addition is a meaningful signal in itself. The sequence is not “disclosed publicly, then attacked within hours” — the more defensible reading is that exploitation was already observed by the time the NVD record went live. VulnCheck’s feed separately marks exploit availability as active, though that claim is single-sourced and carries medium confidence on its own.

Cisco’s own recent KEV history is the wider pattern here. Three distinct Cisco enterprise products landed on the catalog inside eight days: Cisco Secure Firewall Management Center via CVE-2026-20079 on September 9, this Secure Email Gateway flaw on September 14, and Cisco Identity Services Engine via CVE-2026-76460 on September 16, since scored CVSS 10.0 by NVD. Each is a different product line with a different root cause, so this is not one advisory being counted three times — it is three separate perimeter or identity control planes under confirmed attack in the same week.

Evidence and confidence

The record splits cleanly along the two axes that matter, and they do not agree:

  • High confidence — exploitation status and KEV date. CISA is the authoritative source for whether a vulnerability is being exploited, and VulnCheck’s feed independently agrees on both the fact and the September 14 date. The CWE-89 classification is triple-sourced.
  • Medium confidence — the CVSS 9.8 score, the vector, and the technical description. All three trace to NVD alone in our ingested provenance, with no corroborating second source and no contradicting one either. No source conflict exists on any field; the limitation is corroboration, not disagreement.
  • Unknown — exploitation probability. No EPSS score has been ingested for this CVE, so there is no percentile to sharpen patch sequencing beyond the binary fact of KEV listing.

Our data also carries no affected-version range and no fixed-release number for this CVE. Cisco’s advisory cisco-sa-esa-inj-2bLVGmhX is the authoritative reference for both; treat any version claim not sourced from it as unverified.

Why this matters

KEV listing changes the arithmetic that a bare CVSS score cannot. A 9.8 with no observed exploitation is a scheduling problem; a 9.8 that CISA has confirmed in the wild is a response problem, and for US federal civilian agencies it carries a remediation obligation under Binding Operational Directive 26-04. CISA’s own entry for this CVE directs stakeholders to apply vendor mitigations under that directive, to evaluate each asset’s internet exposure, and to discontinue use of the product where no mitigation is available.

For everyone else the practical question is compensating controls, and this flaw is unusually unkind on that front. Where an authenticated management-interface bug can often be contained by restricting who can reach the interface, a mail gateway’s exposed surface is the mail itself. Our source data carries no vendor-published workaround, and we will not invent one — verify against Cisco’s advisory whether any interim configuration change is offered, and if none is, the upgrade is the mitigation.

Frequently Asked Questions

What is CVE-2026-76461? A CVSS 9.8 SQL injection vulnerability (CWE-89) in the email-parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway that, per NVD, allows an unauthenticated remote attacker to execute arbitrary SQL statements and reach command execution with root privileges on the underlying operating system.

Is CVE-2026-76461 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 14, 2026, and VulnCheck’s KEV feed independently records the same date and exploitation status.

Which versions of Cisco Secure Email Gateway are affected? Our ingested source data does not carry an affected-version range or a fixed release for this CVE. Cisco’s security advisory cisco-sa-esa-inj-2bLVGmhX is the authoritative source for both.

Does authentication or user interaction protect against it? No. NVD’s CVSS vector records no required privileges and no required user interaction, which is consistent with a flaw triggered during the parsing of inbound mail.

How does this compare with the other Cisco CVEs on KEV this month? It is the second of three distinct Cisco products added to the catalog between September 9 and September 16, 2026. CVE-2026-20079 in Secure Firewall Management Center scores higher at 10.0; this flaw and that one share a vendor and an exposure profile, not a root cause.

Is this related to the Sangoma Switchvox flaw also on KEV this month? Only by vulnerability class. CVE-2026-9586 is also a CWE-89 unauthenticated SQL injection in a network appliance carrying the same 9.8 score, but it affects a different vendor and product with no shared code or advisory.


Severity, vector, and technical detail sourced from the National Vulnerability Database record for CVE-2026-76461; exploitation status and remediation guidance from the CISA Known Exploited Vulnerabilities catalog, with corroborating exploitation status from VulnCheck’s KEV feed. Vendor advisory: Cisco Security Advisory cisco-sa-esa-inj-2bLVGmhX. Aggregated September 17, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools