Skip to content
Threat Feed
critical threat exploited

Active Exploitation of SQL Injection in Cisco Secure Email Gateway

Cisco has confirmed active exploitation of a SQL injection vulnerability (CVE-2026-76461) affecting multiple versions of Cisco Secure Email Gateway and Secure Email and Web Manager products.

CVE search metadata

CVE search record: CVE-2026-76461. Severity: critical. CVSS: 9.8. KEV: no. Product: Cisco AsyncOS for Cisco Secure Email Gateway (< 15.5.5-014, < 16.0.4-302, < 16.5.0-780), Cisco Secure Email Gateway (< 15.5.5-014, < 16.5.0-780), Cisco Secure Email and Web Manager (< 15.5.5-006, < 16.5.0-429). Brief: Active Exploitation of SQL Injection in Cisco Secure Email Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-sql-injection/

Cisco has issued a security advisory regarding a SQL injection vulnerability identified as CVE-2026-76461, which impacts Cisco AsyncOS for Cisco Secure Email Gateway, Cisco Secure Email Gateway, and Cisco Secure Email and Web Manager. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary SQL commands on the underlying database of the affected appliance, potentially leading to unauthorized data exfiltration or system compromise. Cisco reports that this vulnerability is being actively exploited in the wild, and it has been subsequently added to the CISA Known Exploited Vulnerabilities (KEV) Catalog. The flaw necessitates an immediate upgrade to the patched versions provided by the vendor to remediate the exposure.

Impact

Successful exploitation of CVE-2026-76461 allows unauthorized attackers to interact with the backend databases of affected Cisco Secure Email appliances. Given the sensitivity of email security gateways, successful exploitation could lead to the exposure of configuration data, message metadata, or other system information. The inclusion of this CVE in the CISA KEV catalog underscores the high risk of widespread exploitation against organizations utilizing these gateway appliances in their perimeter defenses.

Recommendation

  1. Patch all affected Cisco products immediately to the recommended versions listed in the vendor advisory: Upgrade Cisco AsyncOS for Cisco Secure Email Gateway to 15.5.5-014, 16.0.4-302, 16.5.0-780 or later.
  2. Upgrade Cisco Secure Email Gateway to version 15.5.5-014, 16.5.0-780 or later.
  3. Upgrade Cisco Secure Email and Web Manager to 15.5.5-006, 16.5.0-429 or later.
  4. Monitor web access logs on these appliances for anomalous HTTP requests containing SQL syntax (e.g., SELECT, UNION, SLEEP) targeting administrative or API endpoints.
  5. Review the official Cisco security advisory (cisco-sa-esa-inj-2bLVGmhX) for further technical details and guidance.

Immediate actions

Upgrade affected Cisco Secure Email Gateway and Manager instances to fixed versions per advisory

IT Operations 24h

Mitigations

Patch affected Cisco products to versions 15.5.5-014, 16.0.4-302, 16.5.0-780 or higher

immediate IT Operations

CVE-2026-76461