Arbitrary Command Execution Vulnerability in Cisco Secure Email Gateway
CVE-2026-76461
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 14 September 2026
Badges
What is CVE-2026-76461?
CVE-2026-76461 is a critical vulnerability found in Cisco Secure Email Gateway, which operates on Cisco's AsyncOS software. This email security solution plays a pivotal role in protecting organizations from various email-based threats, including phishing and malware. The identified vulnerability arises from insufficient validation within the email parsing mechanism. As a result, an unauthenticated remote attacker can exploit this flaw by sending a specially crafted email containing malicious SQL statements. If successfully executed, this could lead to arbitrary command execution with root privileges on the system’s underlying operating system, severely compromising an organization’s security posture. The potential for such command execution poses a considerable risk, as it allows attackers to manipulate system operations, access sensitive data, and deploy further malicious activity without authorization.
Potential impact of CVE-2026-76461
-
Unauthorized System Access: Exploitation of this vulnerability could grant attackers root-level access to the underlying operating system of the Cisco Secure Email Gateway. This level of access could enable them to manipulate system configurations, install malicious software, or carry out other harmful actions unchecked.
-
Data Breach and Leakage: With control over the email gateway system, attackers could potentially access sensitive organizational data transmitted through email. This exposure may lead to significant data breaches, risking confidential information and violating compliance regulations.
-
Widespread Malware Distribution: The ability to execute arbitrary commands may allow cybercriminals to disseminate further malware or ransomware throughout the network, potentially affecting additional systems and leading to larger-scale disruptions or data loss across the organization.
CISA has reported CVE-2026-76461
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-76461 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Cisco Secure Email 14.0.0-698
Cisco Secure Email 13.5.1-277
Cisco Secure Email 13.0.0-392
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Week in review: Cisco patches exploited email gateway 0-day, Revolut breach - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far
3 weeks ago
Attackers use SQL injection emails to root Cisco gateways
Key points Cisco warns attackers are exploiting a previously unknown flaw, CVE-2026-76461, rated 9.8 out of 10.0, to run arbitrary commands as root on Secure Email Gateway appliances. No login is required,...
3 weeks ago
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution | eSecurity Planet
Cisco Secure Email Gateway flaw CVE-2026-76461 is actively exploited. See affected AsyncOS versions, fixed releases, and compromise checks now.
4 weeks ago
References
EPSS Score
28% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🥇
Vulnerability reached the number 1 worldwide trending spot
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 💰
Used in Ransomware
- 📰
First article discovered by Securityweek
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved