The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Cisco Secure Email Gateway, identified as CVE-2026-76461, to its Known Exploited Vulnerabilities (KEV) catalog. This addition mandates that federal civilian executive branch (FCEB) agencies address the flaw by September 17, 2026, to protect their networks from active exploitation.
Cisco confirmed that the vulnerability is a zero-day issue, meaning it was being exploited in the wild before a patch was available. The flaw, which carries a CVSS score of 9.8, allows an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This is achieved by sending specially crafted email messages containing malicious SQL statements.
The vulnerability stems from insufficient validation in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. An attacker can exploit this weakness to inject arbitrary SQL statements, leading to command execution with root privileges.
Cisco's advisory explicitly states that the vulnerability affects both physical and virtual deployments of Cisco Secure Email Gateway, regardless of their configuration. The company has not identified any workarounds to mitigate the issue.
Cisco's Product Security Incident Response Team (PSIRT) became aware of active exploitation. To detect potential compromise, organizations are advised to review their `mail_logs` for suspicious SQL statements. A non-exhaustive example of a malicious SQL statement to look for is "COPY.*TO PROGRAM". If the device is part of a cluster, logs for each device in the cluster should be examined.
For customers utilizing Secure Email Cloud, direct log review may not be possible. However, Cisco has indicated that customers with detected malicious activity in their cloud environments were contacted directly.
CISA's inclusion of CVE-2026-76461 in its KEV catalog aligns with Binding Operational Directive (BOD) 22-01, which aims to reduce significant risks posed by known exploited vulnerabilities. While the directive specifically applies to FCEB agencies, CISA also recommends that private sector organizations review the catalog and address these vulnerabilities within their own infrastructures.






