Vulnerability threat dossier

CVE-2026-76461

ciscosecure email gateway virtual appliance c100v

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

VTP deterministic threat54.6of 100 · CVSS excluded

VTP analyst assessment

Cisco Secure Email Gateway command execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence94%
Public exploitation · VTP factKEV

Assessment

Rapid7 reports active exploitation of this Cisco Secure Email Gateway vulnerability, and CISA KEV lists it as exploited. A crafted email can trigger SQL injection and commands with root privileges.

Why it matters

  • The email parser is the reachable attack surface; exploitation could fully compromise the underlying appliance.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The supplied sources do not identify the attacker or affected customer population.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Cisco Secure Email Gateway with AsyncOS, apply Cisco remediation urgently.

AI baseline history (8)
  1. BASELINE ASSESSED
    Cisco Secure Email Gateway command executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Exploited Cisco Secure Email Gateway command executiongpt-5.6-terra · low
  3. BASELINE ASSESSED
    Cisco Secure Email Gateway SQL injection is exploited globallygpt-5.6-terra · low
  4. BASELINE ASSESSED
    Cisco Secure Email Gateway command executiongpt-5.6-terra · low
  5. BASELINE ASSESSED
    Known-exploited Cisco Secure Email Gateway command executiongpt-5.6-terra · low
  6. BASELINE ASSESSED
    Cisco Secure Email Gateway SQL injectiongpt-5.6-terra · low
  7. BASELINE ASSESSED
    Cisco Secure Email Gateway root command executiongpt-5.6-terra · low
  8. BASELINE ASSESSED
    Cisco Secure Email Gateway SQL injectiongpt-5.6-terra · low
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.2898th percentile · prediction
Evidence confidence86%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.28; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EPSS MATERIAL INCREASEEPSS changed materially from 0.02 to 0.28
ACTIVE EXPLOITATIONActive Exploitation
ZERO DAYZero Day
POC AVAILABLEPoc Available
URGENT PATCHINGUrgent Patching
RESEARCH PUBLICATIONNew technical research
CERT ADVISORYNew CERT advisory
03

Claim provenance

Evidence and source independence

7publications detected
7underlying evidence chains

3 primary sources · 0 dependent secondary reports · 4 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONSOURCE REPORTS ACTIVE EXPLOITATION
82%claim confidence
INDEPENDENTreport:5871331d48d217931a9b6cbc629b3352d7befc2ea4bbcf914d6a43cedb16b36fACTIVE
Evidence
Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
86%claim confidence
INDEPENDENTreport:5871331d48d217931a9b6cbc629b3352d7befc2ea4bbcf914d6a43cedb16b36fACTIVE
Evidence
Source claimPOC AVAILABLEPUBLICATION REPORTS POC
78%claim confidence
INDEPENDENTreport:5871331d48d217931a9b6cbc629b3352d7befc2ea4bbcf914d6a43cedb16b36fACTIVE
Evidence
Source claimURGENT PATCHINGSOURCE URGES URGENT PATCHING
82%claim confidence
INDEPENDENTreport:5871331d48d217931a9b6cbc629b3352d7befc2ea4bbcf914d6a43cedb16b36fACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:6f6828cc92515de8b483846690b136acf4b1c00209bd1f35db675d5121b40008ACTIVE
Evidence
Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:e6c70a2288804bdf56dd114f32f80983def4dadf6ee366cd5e9d4ef29281b26aACTIVE
Evidence
04

Event history

Threat timeline

  1. 17:4525 Sept
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.02 to 0.28

    Predictive context changed; this is not exploitation evidence.

  2. 12:2215 Sept
    ACTIVE EXPLOITATION

    Active Exploitation

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 12:2215 Sept
    ZERO DAY

    Zero Day

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

  4. 12:2215 Sept
    POC AVAILABLE

    Poc Available

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

  5. 12:2215 Sept
    URGENT PATCHING

    Urgent Patching

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

  6. 12:2215 Sept
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-76461.

  7. 06:1115 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  8. 05:1815 Sept
    ZERO DAY

    Zero Day

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  9. 00:0015 Sept
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-76461.

  10. 16:0014 Sept
    VENDOR ADVISORY

    New vendor advisory

    Cisco Product Security Incident Response Team published evidence linked to CVE-2026-76461.

  11. 00:0014 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Cisco Secure Email Gateway SQL Injection Vulnerability

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX <br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-76461

CVE-2026-76461
Separate evidence group
Original

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker

CVE-2026-20130CVE-2026-20176CVE-2026-20192CVE-2026-20194CVE-2026-20211CVE-2026-20234CVE-2026-20237CVE-2026-20242CVE-2026-20282CVE-2026-20283CVE-2026-20284CVE-2026-20287CVE-2026-20305CVE-2026-20306CVE-2026-20307CVE-2026-20322CVE-2026-20324CVE-2026-20325CVE-2026-20326CVE-2026-20329CVE-2026-20330CVE-2026-20331CVE-2026-20332CVE-2026-20333CVE-2026-20334CVE-2026-20335CVE-2026-20336CVE-2026-20340CVE-2026-20341CVE-2026-20342CVE-2026-20343CVE-2026-20344CVE-2026-20353CVE-2026-20360CVE-2026-20361CVE-2026-76409CVE-2026-76412CVE-2026-76413CVE-2026-76420CVE-2026-76423CVE-2026-76424CVE-2026-76425CVE-2026-76426CVE-2026-76427CVE-2026-76428CVE-2026-76440CVE-2026-76441CVE-2026-76442CVE-2026-76443CVE-2026-76460CVE-2026-76461
Separate evidence group
Original

CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authentication. An attacker can reportedly trigger the vulnerability by sending a specially crafted email through a vulnerable gateway. CVE-2026-76461 was added to CISA's Known Exploited Vulnerabilities ( KEV ) catalog on the same day as the vendor disclosed the vulnerability, indicating that CVE-2026-76461 was exploited as a zero-day prior to disclosure. Cisco noted that their PSIRT became aware of active exploitation in September 2026. At the time of publication, there is no public proof-of-concept exploit code available, and no attribution for the current threat actor activity. Mitigation guidance Organizations running Cisco Secure Email Gateway should prioritize upgrading to a vendor-supplied fixed version on an emergency basis, outside of normal patching cycles. Affected Version Fixed Version 15.5 and earlier 15.5.5-014 16.0 16.0.4-302 16.5 16.5.0-780 Given the reported active exploitation and the ability to achieve unauthenticated root-level command execution through malicious email processing, organizations should prioritize patching rather than relying solely on network controls or monitoring. Cisco also strongly recommends that customers migrate to the latest product version, 16.5.0-780. For the latest remediation guidance, see the vendor advisory . Indicators of compromise The following indicators of compromise for CVE-2026-76461 were reported within the Cisco security advisory . To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device. The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs: cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs] The presence of any entry in the output may indicate malicious activity. Rapid7 customers Exposure Command, InsightVM, and Nexpose Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-76461 with a vulnerability check expected to be available in the September 16 content release. Updates September 15, 2026: Initial publication.

CVE-2026-76461
Separate evidence group
Original

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]

CVE-2025-20393CVE-2026-20079CVE-2026-20353CVE-2026-76440CVE-2026-76441CVE-2026-76443CVE-2026-76461
Separate evidence group
Original

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

CVE-2026-76461
Separate evidence group
Original

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek .

CVE-2025-20393CVE-2026-20079CVE-2026-20316CVE-2026-76461
Separate evidence group
Original

Multiples vulnérabilités dans les produits Cisco (15 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Cisco. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une injection SQL (SQLi). Cisco indique que la vulnérabilité CVE-2026-76461 est...

CVE-2026-20353CVE-2026-76440CVE-2026-76441CVE-2026-76442CVE-2026-76443CVE-2026-76461
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score54.6vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction5.65 / 20
Exploit availability7.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration2 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-89
CPE records
7
Deterministic history records
19
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.