CISA added a critical SQL injection flaw in Cisco AsyncOS for Secure Email Gateway to the Known Exploited Vulnerabilities catalog on 2026-09-14. KEV listing indicates CISA has evidence the flaw has been exploited in the wild; the catalog entry does not detail the nature or scope of that evidence. Cisco PSIRT scored the issue CVSS 9.8 and states that it could allow an unauthenticated, remote attacker to execute commands with root privileges on the affected device.
A caveat on the identifier: the CVE number reported alongside this entry (given as CVE-2026-76461) falls outside the CVE-2026 assignment range in issue as of mid-September 2026, which is still in the five-figure 2026-1xxxx band. Because the number as reported could not be reconciled with that range, it is treated here as unverified and is not used as the anchor for this brief; readers should confirm the correct identifier directly against the NVD record and the KEV catalog entry. The vendor advisory (cisco-sa-esa-inj-2bLVGmhX) is the authoritative reference for the underlying vulnerability.
What Is It
The vulnerability is a SQL injection issue (CWE-89) in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. Per Cisco, insufficient validation during email parsing could allow an unauthenticated, remote attacker to send a crafted email message containing malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, which Cisco says could lead to command execution with root privileges on the underlying operating system.
Cisco PSIRT scored it CVSS 3.1 base 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Why It Matters
The attack vector is a message sent through the device; the exact traffic a mail gateway exists to process. There is no authentication requirement, no user interaction, and low attack complexity, and the potential payoff, per the vendor, is root on the host.
CISA's SSVC assessment marks exploitation as active, automatable yes, and technical impact total. Known ransomware campaign use is listed as Unknown. The KEV entry also flags forensic triage as required. Treat the exploitation signal as CISA's assessment rather than as independently corroborated public reporting; no public technical analysis of in-the-wild activity was available at the time of writing.
What's Vulnerable
Cisco Secure Email (AsyncOS) versions listed as affected by Cisco PSIRT span the 13.x through 16.x trains, including:
- 13.0.0-392, 13.0.5-007, 13.5.1-277, 13.5.4-038
- 14.0.0-698, 14.2.0-620, 14.2.1-020, 14.3.0-032
- 15.0.0-104, 15.0.1-030, 15.0.3-002, 15.0.5-016
- 15.5.0-048, 15.5.1-055, 15.5.2-018, 15.5.3-022, 15.5.4-012
- 16.0.0-050, 16.0.0-054, 16.0.1-017, 16.0.2-112, 16.0.3-044, 16.0.4-016
Patch Status
CISA's required action: apply mitigations per vendor instructions, in compliance with BOD 26-04 "Prioritizing Security Updates Based on Risk" and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
The remediation due date is 2026-09-17: three days after KEV addition. NVD status is "Undergoing Analysis."
Sources
- Cisco Security Advisory (cisco-sa-esa-inj-2bLVGmhX), https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
- CISA Known Exploited Vulnerabilities Catalog (query uses the unverified identifier as reported), https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461
- NVD, record for the identifier as reported, unverified, https://nvd.nist.gov/vuln/detail/CVE-2026-76461
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk