CISA says a Cisco email gateway bug is under attack

Published

A crafted email message is enough to take root control of a Cisco Secure Email Gateway, and CISA says somebody is already doing it. The agency added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 14, on evidence of active exploitation.

The alert itself is a single line of description, "Cisco Secure Email Gateway SQL Injection Vulnerability", plus the directive boilerplate. It carries no attacker, no volume and no indicators. The mechanism comes from the NVD record, which scores the flaw 9.8 out of 10.

The appliance whose job is reading strangers' mail

The flaw sits in the email parsing logic of Cisco AsyncOS, the operating system that runs the Secure Email Gateway. Validation there is insufficient, so an attacker can send a message containing malicious SQL statements, which is database instruction text the appliance was never meant to run, and have it executed. NVD states that a successful exploit leads to command execution with root privileges on the underlying operating system, reached by an unauthenticated, remote attacker.

The delivery route is what makes this one awkward. A mail gateway's entire purpose is to accept messages from people it has never met and inspect them, so there is no network boundary left to tighten and no user to train out of clicking. The appliance also sits in front of the mail flow, which is a useful place to stand for anyone whose interest is other people's correspondence.

What the catalog entry does not tell you

CISA names no threat actor, no affected AsyncOS releases, no exploitation volume and no indicators of compromise, and does not say whether the activity is linked to ransomware. Cisco's own security advisory is the authority on which releases are affected and which fixed builds to move to, and that is where an administrator should check a specific appliance's exposure. Nothing in the KEV listing supports a more detailed picture than that, and reading one into it would be guesswork.

Patch it, then look for what arrived before the patch

Federal civilian agencies are bound by Binding Operational Directive 26-04, which requires them to prioritize rapid remediation of high risk catalog entries on publicly exposed assets that grant total control after exploitation, and to establish whether attackers reached the system before the update went on. That second obligation is the part every other organization should copy here. An appliance compromised at root level is not made clean by installing a newer build over the top of it, so the work is a patch followed by an actual look at the box.

CISA encourages all organizations, not only agencies, to treat the catalog as a prioritization list. Internet facing appliances keep earning places on it because they are exposed by design, rarely rebuilt, and trusted by everything behind them. We covered the September 11 batch that put ScreenConnect on a federal clock, and separately a Russian implant found quietly watching traffic on Cisco Firepower Management Center. A mail gateway belongs in the same category of asset, and it has now joined the same list.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions