we_are_coded.by CODE · The world, decoded
БГ
Cisco

A hole in Cisco's email gateway gives root with a single email, and CISA gave agencies three days

Cisco Security Advisory · event date: 14 September 2026Security

CVE-2026-76461 is an SQL injection in the mail parsing of Cisco AsyncOS. It needs no account, does not depend on configuration and is already being used in attacks. There is no workaround, only the upgrade.

In short
  • The attacker sends a crafted email, the gateway parses it, and during parsing it can run someone else's commands with root privileges.
  • Physical and virtual Secure Email Gateway devices are affected regardless of configuration. The fix is in 15.5.5-014, 16.0.4-302 and 16.5.0-780.
  • In a cluster, a breached gateway can hand over the keys to the others, so Cisco recommends restoring the whole cluster.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The mail gateway is the place everything you do not know passes through. Its job is to read strangers' letters before you have opened a single one of them.

That is exactly where the hole is. The attacker does not come in with a password and does not wait for an employee to click a link. They send an email. The gateway inspects it the way it inspects every other one, and while inspecting it, can run someone else's command with the highest privileges on the system.

The facts: on 14 September 2026 Cisco published an advisory for CVE-2026-76461, an SQL injection in the email parsing logic of AsyncOS Software for Cisco Secure Email Gateway, scored 9.8 on CVSS. An unauthenticated remote attacker sends a crafted email and can execute commands with root privileges on the underlying operating system. Physical and virtual devices are affected regardless of configuration; Secure Email and Web Manager and Secure Web Appliance are not affected. There is no workaround. The fix is in 15.5.5-014, 16.0.4-302 and 16.5.0-780, and for anything below 16.5 Cisco recommends moving straight to 16.5.0-780. Per Cisco, its security team became aware of active exploitation in September; devices in Secure Email Cloud have already been upgraded, and cloud customers with signs of compromise have been contacted directly. On 14 September CISA added the vulnerability to its catalogue of exploited vulnerabilities, with a deadline for federal agencies of 17 September. On 17 September the advisory was updated with guidance for clustered devices.

What the advisory says further down

Two details weigh more than the 9.8 score. The first: after a successful attack the intruder may have root and can wipe their tracks. That is why Cisco itself advises not to trust only the device's own logs, but to check the firewall and the network around it for unexpected uploads going out.

The second is about clusters. Gateways in a cluster recognise each other with SSH keys, and if one is breached, the keys may already be with the attacker. The recommendation is to restore every member of a cluster that contains at least one compromised device, not only the infected one.

A breached gateway in a cluster is rarely just one breached gateway.

For checking, Cisco gives a concrete direction: search mail_logs for suspicious SQL statements of the COPY ... TO PROGRAM kind. An empty result is not yet a guarantee, because Cisco itself calls the example non-exhaustive. A full one means you leave the news and call Cisco support.

If you run such a gateway on your own hardware or in a virtual machine, you upgrade today, without waiting for a maintenance window. The three days are the US agencies' deadline, and the attacks are already running.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Cisco Security Advisory - Cisco Secure Email Gateway SQL Injection Vulnerability (cisco-sa-esa-inj-2bLVGmhX), 14.09.2026→CISA - Known Exploited Vulnerabilities Catalog, CVE-2026-76461
Original: https://wearecoded.com/en/articles/cisco-imeyl-shlyuz-root-s-edno-pismo.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news