Cisco Email Gateway Zero-Day Rated 9.8; CISA Deadline 17 Sept

Cisco published an advisory on 14 September 2026 for CVE-2026-76461, a SQL injection flaw in the email-parsing logic of Cisco AsyncOS Software for Secure Email Gateway. The company rates it Critical with a CVSS base score of 9.8. "This vulnerability is due to insufficient validation in the email parsing logic," Cisco wrote. "An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device... leading to command execution with root privileges on the underlying operating system." No authentication, no user interaction and no workaround.
The attack surface is the appliance's day job. A Secure Email Gateway exists to parse inbound mail, so the malicious message does not need to reach an administrator or a management interface — it only needs to be delivered. Cisco says the flaw affects both physical and virtual Secure Email Gateway appliances regardless of configuration, and that Secure Email and Web Manager and Secure Web Appliance are not affected.
The reason this matters on 17 September is the clock. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on 14 September and set a remediation due date of 17 September for US federal civilian agencies, under Binding Operational Directive 26-04. That is a three-day window, among the shortest CISA issues, and the entry is flagged for forensic triage. Cisco's own advisory states that "in September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," and says the bug was found while resolving a Cisco TAC support case rather than in an internal review.
Patching alone may not close the incident. Because a successful exploit yields root, Cisco warns that "evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors," and advises administrators to check network and firewall logs outside the appliance for unexpected uploads to external IP addresses. Cisco's published indicator is to grep each cluster device's mail_logs for suspicious SQL statements. The fixed releases are 15.5.5-014, 16.0.4-302 and 16.5.0-780, with Cisco strongly recommending a move to 16.5.0-780. Cisco has already upgraded all Secure Email Cloud devices to that release and says it directly contacted cloud customers whose devices showed malicious activity.
Who is behind the attacks, and how many appliances were reached, is not established in Cisco's advisory. BleepingComputer reported that Shadowserver tracks more than 400 exposed Secure Email Gateway appliances, without saying how many are already patched. Separately, CISA added a different Cisco flaw, CVE-2026-76460 in Identity Services Engine, to the same catalog on 16 September with a 19 September deadline.
Sources
- Cisco Security Advisory cisco-sa-esa-inj-2bLVGmhXPrimary source
- CISA — Known Exploited Vulnerabilities CatalogPrimary source
- CISA — BOD 26-04: Prioritizing Security Updates Based on RiskPrimary source
- BleepingComputerSecondary
- Help Net SecuritySecondary
- eSecurity PlanetSecondary
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.