




Threat Insight
Cisco has published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. If exploited, the vulnerability could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance by sending a specially crafted email through a vulnerable gateway[1].
Cisco Secure Email Gateway processes inbound and outbound email traffic as part of normal operation. According to Cisco[1], exploitation does not require authentication or access to an administrative interface. An attacker can reportedly trigger the vulnerability through malicious email content processed by the gateway.
Cisco has stated that it became aware of active exploitation in September 2026, indicating that the vulnerability was exploited prior to public disclosure. [1]
CVE-2026-76461
Cisco Secure Email Gateway (Cisco AsyncOS Software) versions[1]:
15.5 and earlier
16.0
16.5
Cisco confirms active exploitation during September 2026[1].
The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog.
Truesec recommends that you upgrade to one of the fixed versions below.
The vulnerability is fixed in Cisco Secure Email Gateway (Cisco AsyncOS Software) versions[1]:
15.5.5-014
16.0.4-302
16.5.0-780
Detection
To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device. The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs[1]:
cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]
The presence of any entry in the output may indicate malicious activity[1].
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。