Cisco published an advisory on September 14 for CVE-2026-76461, a critical SQL injection in AsyncOS for Secure Email Gateway, and the flaw is already being exploited in the wild. The vulnerability carries a CVSS v3.1 base score of 9.8. An unauthenticated remote attacker can execute arbitrary commands with root privileges by sending a specially crafted email through an affected gateway, with no admin interface access or authentication required.
Cisco's Product Security Incident Response Team learned of active exploitation in September 2026, and the flaw was added to the CISA Known Exploited Vulnerabilities catalog the same day it was disclosed. That KEV addition indicates the vulnerability was exploited as a zero-day before disclosure. Cisco has not attributed the activity to any threat actor, and no public proof-of-concept exploit code existed at publication.
Rapid7 urges administrators to treat the fix as an emergency rather than waiting for routine patch cycles, and to prioritize upgrades over leaning on monitoring or network controls alone. Cisco, for its part, strongly recommends moving to version 16.5.0-780, the latest release. Organizations running 15.5 or earlier should move to 15.5.5-014, while those on 16.0 should install 16.0.4-302.
Cisco's advisory includes indicators of compromise and detection guidance. Administrators can review mail_logs for suspicious SQL statements to confirm attempted exploitation, and should check the logs of every cluster device if the appliance is clustered. One detection example uses grep for COPY.*TO PROGRAM in IronPort Text Mail Logs, and any entry in that output may indicate malicious activity.
Rapid7 customers can assess exposure through Exposure Command, InsightVM, and Nexpose, with a vulnerability check expected in the September 16 content release. Secure Email Gateway, formerly the IronPort Email Security Appliance, inspects inbound and outbound mail for threats such as phishing, malware, and spam.
The disclosure follows a run of critical flaws in widely deployed network and email products. In August, Rapid7 flagged CVE-2026-19490, a Citrix NetScaler ADC and NetScaler Gateway issue rated 9.3 under CVSS v4.0. SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 were also reported as exploited in the wild, chaining to unauthenticated remote code execution. Earlier in September, Rapid7 covered CVE-2026-85706, a GitLab path traversal with a CVSS v3.1 score of 10.0.
Cisco has dealt with an email gateway emergency before. A prior AsyncOS flaw, CVE-2025-20393, carried a CVSS score of 10.0 and granted root access through a Spam Quarantine feature exposed to the internet, and Cisco Talos attributed that campaign to UAT-9686. At the time of that advisory no patch was available, CISA set a December 24 deadline for federal agencies, and Cisco said rebuilding appliances was the only viable eradication option. This time a fixed release exists, but the exploitation is already underway.













