CVE-2026-76461 carries a CVSS score of 9.8 and, Cisco warns, is being actively exploited in the wild — a vulnerability that can let an unauthenticated attacker send a crafted email and gain root command execution on affected devices.
The vulnerability: insufficient validation in AsyncOS email parsing
Cisco has described CVE-2026-76461 as a case of insufficient validation in the email parsing logic of AsyncOS Software for Cisco Secure Email Gateway. "An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," Cisco said in a Monday advisory. A successful exploit, the company added, "could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system."
Cisco warned that "Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges," and noted that attackers with that level of access "may remove or hide" evidence of exploitation, complicating detection and forensic efforts.
Affected products and available fixes
The flaw affects Cisco Secure Email Gateway — both physical and virtual appliances — "regardless of device configuration." Cisco explicitly stated that other products, including Secure Email and Web Manager and Secure Web Appliance, are not impacted.
- AsyncOS 15.5 and earlier — fixed in 15.5.5-0141
- AsyncOS 16.0 — fixed in 16.0.4-302
- AsyncOS 16.5 — fixed in 16.5.0-780
Cisco said there are no workarounds other than updating to the latest supported version.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleIndicators of compromise and detection steps Cisco provided
Cisco shared concrete indicators of compromise (IoCs) and log-review guidance for administrators investigating potential abuse. The vendor advised teams to:
- Review mail_logs for suspicious SQL statements and, if the device is part of a cluster, examine the logs on every cluster member.
- Run the following command to detect potentially malicious SQL statements: cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]. Cisco said the presence of any entry in that output may indicate malicious activity.
- Cross-check network and firewall logs outside the impacted device to look for anomalous activity, including unexpected uploads initiated from the affected device to external IP addresses or downloads from malicious IP addresses.
Cisco also said it has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected, but the company did not disclose the scale of the attacks.
CISA adds CVE-2026-76461 to KEV; federal patching deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalog. That placement requires Federal Civilian Executive Branch agencies to apply the patches by September 17, 2026 — a date CISA set in the KEV listing.
The inclusion in the KEV underscores the federal requirement for prompt remediation and places a short, concrete deadline on public-sector operators using affected Cisco Secure Email Gateway appliances.
How security teams, federal agencies, and affected enterprises should respond
- Security teams and technologists: prioritize applying the AsyncOS updates listed above; run the recommended grep searches and cluster-wide log reviews; and expand forensic checks to upstream and downstream network logs because attackers with root access may have removed local traces.
- Federal Civilian Executive Branch agencies and compliance officers: treat the CISA KEV listing and the September 17, 2026 deadline as mandatory action items and verify that affected devices have been updated to the fixed AsyncOS releases.
- Affected enterprises and procurement leaders: confirm whether deployed Secure Email Gateway appliances (physical or virtual) are on an impacted AsyncOS release, ensure patch deployment across clusters, and follow Cisco’s guidance to review external network activity for unexpected uploads or downloads tied to those devices.
Related activity: Fortinet VPN credential attacks noted by Arctic Wolf
The Cisco advisory and CISA action arrive days after Arctic Wolf reported large-scale credential attacks targeting internet-facing Fortinet VPN appliances in late August 2026. Arctic Wolf said the activity occurred in two sustained waves from August 26 through August 28, 2026 and generated tens of millions of authentication failures. Researcher Kyle Siddall observed that the actor used organization-specific usernames, corporate email addresses, affiliate accounts, and common administrative identities — indicating access to previously collected or enumerated identity information. In one observed case, a successful Fortinet VPN authentication from the IP address "158.94.211[.]14" was followed by malicious activity in the affected environment.
Cisco’s disclosure leaves an immediate operational mandate: patch quickly, hunt widely, and assume that any evidence on compromised devices may have been altered or erased. With CISA’s KEV deadline two days away, the clock is short and the window for containment narrows — yet Cisco has supplied concrete fixes and detection commands that teams can run now.




