• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-76461: pre-auth remote code execution in Cisco Secure Email Gateway

Unauthenticated remote attackers can execute arbitrary commands as root on Cisco Secure Email Gateway by sending specially crafted email messages that exploit a SQL injection in AsyncOS email parsing. CVE-2026-76461 affects multiple AsyncOS releases in the 13.x, 14.x and 15.x branches listed by the vendor (examples include 13.0.0-392, 13.5.1-277, 14.0.0-698, 15.0.0-104). Exploitation requires only the ability to deliver email to the affected SEG device; no prior credentials or user interaction are needed.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.28269
CWE
CWE-89
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a short federal remediation deadline, so prioritize mitigation now and follow Cisco and CISA guidance immediately.

What is CVE-2026-76461?

Unauthenticated remote attackers can execute arbitrary commands as root on Cisco Secure Email Gateway by sending specially crafted email messages that exploit a SQL injection in AsyncOS email parsing. CVE-2026-76461 affects multiple AsyncOS releases in the 13.x, 14.x and 15.x branches listed by the vendor (examples include 13.0.0-392, 13.5.1-277, 14.0.0-698, 15.0.0-104). Exploitation requires only the ability to deliver email to the affected SEG device; no prior credentials or user interaction are needed. The weakness is classified as CWE-89 (SQL Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Cisco Secure Email Gateway are affected?

BRANCHAFFECTEDFIXED
14.x14.0.0-698
13.x13.5.1-277
13.x13.0.0-392
14.x14.2.0-620
13.x13.0.5-007
13.x13.5.4-038
14.x14.2.1-020
14.x14.3.0-032
15.x15.0.0-104
15.x15.0.1-030

Is CVE-2026-76461 being exploited?

CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on 2026-09-14; U.S. federal agencies must remediate by 2026-09-17. Public exploit code is available.

How to fix CVE-2026-76461

  1. Follow Cisco’s advisory and implement any vendor-provided mitigations immediately.
  2. Restrict exposure: limit which systems can receive mail and block or quarantine suspicious inbound messages.
  3. Apply CISA KEV and BOD 26-04 remediation steps for affected assets and cloud services as applicable.
  4. Monitor SEG logs and forensics data for signs of exploit attempts and implement network segmentation to isolate affected appliances.

Frequently asked questions

Is CVE-2026-76461 being actively exploited?

CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on 2026-09-14 and federal agencies were required to remediate by 2026-09-17; public exploit code is available.

Which Secure Email Gateway versions are affected by CVE-2026-76461?

Cisco Secure Email Gateway AsyncOS releases in the 13.x, 14.x and 15.x branches are listed as affected; examples from the vendor list include 13.0.0-392, 13.5.1-277, 14.0.0-698 and 15.0.0-104.

Is there a patch for CVE-2026-76461?

There is no fixed software version listed by the vendor in the provided data; follow Cisco’s advisory and apply recommended mitigations and compensating controls.

Does CVE-2026-76461 require authentication?

No, the vulnerability can be exploited by an unauthenticated remote attacker who can deliver a crafted email to the affected Cisco Secure Email Gateway.

References