Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-15 ยท updated: 2026-09-15 ยท tags: [cve, email-security, remote-code-execution] ยท confidence: high ยท severity: critical ยท affected_sectors: [government, global] ยท au_impact: true

CVE-2026-76461 is a critical remote code execution vulnerability in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway, added to CISA's Known Exploited Vulnerabilities Catalog on 14 September 2026 on the basis of evidence of active exploitation. An unauthenticated, remote attacker can exploit it by sending a crafted email message containing malicious SQL statements through an affected device; successful exploitation executes arbitrary SQL statements and leads to command execution with root privileges on the underlying operating system. Cisco PSIRT rates the flaw 9.8 (critical) โ€” network vector, low complexity, no privileges and no user interaction required โ€” and CISA's own SSVC assessment records exploitation as active, automatable and of total technical impact.

Attribute Detail
CVE CVE-2026-76461
CVSS 9.8 (critical) โ€” CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor / product Cisco โ€” AsyncOS Software for Secure Email Gateway
CWE / class SQL injection in email parsing, leading to unauthenticated remote command execution as root
Reported 2026-09-14
Exploited Yes โ€” KEV-catalogued 14 September 2026 (active, automatable, total technical impact per CISA SSVC)
Published (NVD) 2026-09-14

Defensive notes

Secure email gateways sit inline on mail flow for the whole organisation, so exploitation is reachable by anyone who can send an email to the domain โ€” no authentication or user interaction is needed. CISA's Binding Operational Directive 26-04 requires US federal civilian agencies to prioritise remediation of KEV-listed flaws on publicly exposed assets that grant total control post-exploitation, and to check whether systems were compromised before patching. The same prioritisation is the sensible default elsewhere: patch the gateway, then hunt for signs of pre-patch compromise rather than assuming patching closed the exposure.

Related

  • KEV addition recorded in the digest of 2026-09-15 (Government).
  • The CISA KEV batch of 09โ€“11 September 2026 covered JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, GitLab, Citrix NetScaler, Fortinet and Google Chromium.