CVE-2026-76461 is a critical remote code execution vulnerability in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway, added to CISA's Known Exploited Vulnerabilities Catalog on 14 September 2026 on the basis of evidence of active exploitation. An unauthenticated, remote attacker can exploit it by sending a crafted email message containing malicious SQL statements through an affected device; successful exploitation executes arbitrary SQL statements and leads to command execution with root privileges on the underlying operating system. Cisco PSIRT rates the flaw 9.8 (critical) โ network vector, low complexity, no privileges and no user interaction required โ and CISA's own SSVC assessment records exploitation as active, automatable and of total technical impact.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-76461 |
| CVSS | 9.8 (critical) โ CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Vendor / product | Cisco โ AsyncOS Software for Secure Email Gateway |
| CWE / class | SQL injection in email parsing, leading to unauthenticated remote command execution as root |
| Reported | 2026-09-14 |
| Exploited | Yes โ KEV-catalogued 14 September 2026 (active, automatable, total technical impact per CISA SSVC) |
| Published (NVD) | 2026-09-14 |
Defensive notes
Secure email gateways sit inline on mail flow for the whole organisation, so exploitation is reachable by anyone who can send an email to the domain โ no authentication or user interaction is needed. CISA's Binding Operational Directive 26-04 requires US federal civilian agencies to prioritise remediation of KEV-listed flaws on publicly exposed assets that grant total control post-exploitation, and to check whether systems were compromised before patching. The same prioritisation is the sensible default elsewhere: patch the gateway, then hunt for signs of pre-patch compromise rather than assuming patching closed the exposure.
Related
- KEV addition recorded in the digest of 2026-09-15 (Government).
- The CISA KEV batch of 09โ11 September 2026 covered JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, GitLab, Citrix NetScaler, Fortinet and Google Chromium.