Cisco Email Gateway SQLi Grants Root, Now in KEV
CVE-2026-76461, a SQL injection in Cisco AsyncOS, lets unauthenticated attackers run OS commands as root. CISA added it to KEV on Sept. 14 with a Sept. 17 deadline.

Cisco’s Secure Email Gateway (SEG) has a new entry in the CISA Known Exploited Vulnerabilities catalog: CVE-2026-76461, a SQL injection flaw in AsyncOS that lets an unauthenticated remote attacker execute arbitrary commands on the underlying operating system with root privileges. CISA added it on September 14 with a remediation deadline of September 17 for federal agencies under BOD 26-04.
CVSS score: 9.8 critical. Attack vector: network. Authentication required: none.
Email gateway as a target
Email security gateways sit at the internet edge, processing every inbound message before it reaches internal mail servers. A root shell on one is not a limited beachhead; it is a privileged position on the appliance that handles all inbound traffic for the organization behind it.
SecurityWeek reported active exploitation on September 15. The NVD record confirms the network-accessible, unauthenticated attack vector, and CISA’s KEV listing includes forensics triage requirements alongside the remediation deadline. That specific language typically appears when active incident response is already underway in some federal environments rather than being a precautionary notice.
Remediation
CISA’s KEV entry directs agencies to apply vendor mitigations per Cisco’s advisory instructions. The September 17 deadline under BOD 26-04 is not a suggestion for federal agencies; it is the outer bound. For organizations that cannot deploy the patch in that window, reducing direct internet exposure of SEG instances and staging behind an upstream filtering layer are the short-term options while remediation proceeds.
Same pattern, different product
The Cisco FMC auth bypass exploited in active campaigns two weeks ago and the critical RCE in Nexus 9000 switches earlier this month both landed in KEV inside the same stretch. State-sponsored actors and ransomware groups targeting FMC infrastructure complicated the picture further. Whether this run of Cisco vulnerabilities reflects a concentrated campaign against Cisco products, improved detection, or simply the consequence of a very large installed base providing continuous surface area, Cisco-heavy environments should treat CVE-2026-76461 as an emergency, not a scheduled maintenance item.
- [ CRITICAL ]CVE-2026-76461Cisco Secure Email Gateway SQL Injection Vulnerability
Found this useful? Share it.


