Cybersecurity

Cisco Email Gateway Zero-Day Rated 9.8; CISA Deadline 17 Sept

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Cisco Email Gateway Zero-Day Rated 9.8; CISA Deadline 17 Sept
Photo: Johannes Weber / Wikimedia Commons (CC BY 2.0)
0 0
XWhatsAppTelegramLinkedIn

Cisco published an advisory on 14 September 2026 for CVE-2026-76461, a SQL injection flaw in the email-parsing logic of Cisco AsyncOS Software for Secure Email Gateway. The company rates it Critical with a CVSS base score of 9.8. "This vulnerability is due to insufficient validation in the email parsing logic," Cisco wrote. "An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device... leading to command execution with root privileges on the underlying operating system." No authentication, no user interaction and no workaround.

The attack surface is the appliance's day job. A Secure Email Gateway exists to parse inbound mail, so the malicious message does not need to reach an administrator or a management interface — it only needs to be delivered. Cisco says the flaw affects both physical and virtual Secure Email Gateway appliances regardless of configuration, and that Secure Email and Web Manager and Secure Web Appliance are not affected.

The reason this matters on 17 September is the clock. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on 14 September and set a remediation due date of 17 September for US federal civilian agencies, under Binding Operational Directive 26-04. That is a three-day window, among the shortest CISA issues, and the entry is flagged for forensic triage. Cisco's own advisory states that "in September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," and says the bug was found while resolving a Cisco TAC support case rather than in an internal review.

Patching alone may not close the incident. Because a successful exploit yields root, Cisco warns that "evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors," and advises administrators to check network and firewall logs outside the appliance for unexpected uploads to external IP addresses. Cisco's published indicator is to grep each cluster device's mail_logs for suspicious SQL statements. The fixed releases are 15.5.5-014, 16.0.4-302 and 16.5.0-780, with Cisco strongly recommending a move to 16.5.0-780. Cisco has already upgraded all Secure Email Cloud devices to that release and says it directly contacted cloud customers whose devices showed malicious activity.

Who is behind the attacks, and how many appliances were reached, is not established in Cisco's advisory. BleepingComputer reported that Shadowserver tracks more than 400 exposed Secure Email Gateway appliances, without saying how many are already patched. Separately, CISA added a different Cisco flaw, CVE-2026-76460 in Identity Services Engine, to the same catalog on 16 September with a 19 September deadline.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.