The vulnerability
CVE-2026-76461 is a SQL injection flaw in the email parsing logic of Cisco AsyncOS, the operating system running on Cisco Secure Email Gateway appliances. An unauthenticated remote attacker can send a crafted email through the device, trigger SQL execution inside the parser, and escalate to root command execution on the underlying operating system. CVSS score: 9.8. No credentials required. No user interaction required.
What is affected
Affected versions include AsyncOS 15.5 and all earlier releases, all 16.0.x versions, and all 16.5.x versions. The cloud-delivered Cisco Secure Email Cloud is also affected. If your organization routes inbound email through a Cisco gateway and has not yet patched, treat yourself as exposed.
Active exploitation and CISA deadline
Cisco confirmed active exploitation on September 15, 2026. CISA added the CVE to the Known Exploited Vulnerabilities catalog the same day with a federal civilian agency remediation deadline of September 17. Cisco is aware of exploitation occurring as early as September 2025. Upgrade to AsyncOS 16.5.0-780 (Cisco's preferred path), 16.0.4-302, or 15.5.5-014. Check for evidence of compromise before patching: look for anomalous root-process spawns and unexpected outbound connections from gateway appliances.
The broader point
Email security gateways are high-value targets because every inbound message passes through them before reaching users. An exploitable parser in that path means an attacker who can send your organization an email can own your mail inspection infrastructure. The fact that this reached CVSS 9.8 and was exploited in the wild for potentially a year before public acknowledgment is a reminder that the inspection layer itself needs its own disciplined patch cadence.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need help thinking through your email gateway patch strategy or compromise assessment.