Cyber & AI intelligence
Wasteland.
Briefs indexed2601
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-76461 2026-09-14

Cisco Secure Email Gateway Hit by Critical Unauthenticated SQL Injection (Cisco Advisory cisco-sa-esa-inj-2bLVGmhX)

"CISA added a critical SQL injection flaw in Cisco AsyncOS for Secure Email Gateway to the Known Exploited Vulnerabilities catalog on 2026-09-14. KEV listing indicates CISA has evidence the flaw has been exploited in the…"

CISA added a critical SQL injection flaw in Cisco AsyncOS for Secure Email Gateway to the Known Exploited Vulnerabilities catalog on 2026-09-14. KEV listing indicates CISA has evidence the flaw has been exploited in the wild; the catalog entry does not detail the nature or scope of that evidence. Cisco PSIRT scored the issue CVSS 9.8 and states that it could allow an unauthenticated, remote attacker to execute commands with root privileges on the affected device.

A caveat on the identifier: the CVE number reported alongside this entry (given as CVE-2026-76461) falls outside the CVE-2026 assignment range in issue as of mid-September 2026, which is still in the five-figure 2026-1xxxx band. Because the number as reported could not be reconciled with that range, it is treated here as unverified and is not used as the anchor for this brief; readers should confirm the correct identifier directly against the NVD record and the KEV catalog entry. The vendor advisory (cisco-sa-esa-inj-2bLVGmhX) is the authoritative reference for the underlying vulnerability.

What Is It

The vulnerability is a SQL injection issue (CWE-89) in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. Per Cisco, insufficient validation during email parsing could allow an unauthenticated, remote attacker to send a crafted email message containing malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, which Cisco says could lead to command execution with root privileges on the underlying operating system.

Cisco PSIRT scored it CVSS 3.1 base 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Why It Matters

The attack vector is a message sent through the device; the exact traffic a mail gateway exists to process. There is no authentication requirement, no user interaction, and low attack complexity, and the potential payoff, per the vendor, is root on the host.

CISA's SSVC assessment marks exploitation as active, automatable yes, and technical impact total. Known ransomware campaign use is listed as Unknown. The KEV entry also flags forensic triage as required. Treat the exploitation signal as CISA's assessment rather than as independently corroborated public reporting; no public technical analysis of in-the-wild activity was available at the time of writing.

What's Vulnerable

Cisco Secure Email (AsyncOS) versions listed as affected by Cisco PSIRT span the 13.x through 16.x trains, including:

Patch Status

CISA's required action: apply mitigations per vendor instructions, in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.

The remediation due date is 2026-09-17: three days after KEV addition. NVD status is "Undergoing Analysis."

Sources