The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog.
Cisco disclosed a critical zero-day CVE-2026-76461 this week; the flaw can be exploited remotely without authentication. Attackers can send specially crafted emails containing malicious SQL statements, triggering arbitrary command execution on the underlying system with root privileges. Cisco confirmed the vulnerability is already being exploited in the wild.
“A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.” reads the report published by the networking giant.
“This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.”
According to the advisory, the vulnerability affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration. The company states that there are no workarounds that address this issue.
Recently, the company’s PSIRT became aware of active exploitation of this vulnerability.
Check Secure Email Gateway logs for suspicious SQL statements to detect possible exploitation. If the device is part of a cluster, check every device. Cisco says customers using Secure Email Cloud may not be able to check these indicators themselves, but those with detected malicious activity were contacted directly.
“To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device.” states the advisory. “The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs:
cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]
The presence of any entry in the output may indicate malicious activity.”
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaw by September 17, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)