DIRAS TAKE
Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog with a short federal remediation deadline, so prioritize mitigation now and follow Cisco and CISA guidance immediately.
What is CVE-2026-76461?
Unauthenticated remote attackers can execute arbitrary commands as root on Cisco Secure Email Gateway by sending specially crafted email messages that exploit a SQL injection in AsyncOS email parsing. CVE-2026-76461 affects multiple AsyncOS releases in the 13.x, 14.x and 15.x branches listed by the vendor (examples include 13.0.0-392, 13.5.1-277, 14.0.0-698, 15.0.0-104). Exploitation requires only the ability to deliver email to the affected SEG device; no prior credentials or user interaction are needed. The weakness is classified as CWE-89 (SQL Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Cisco Secure Email Gateway are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 14.x | 14.0.0-698 | |
| 13.x | 13.5.1-277 | |
| 13.x | 13.0.0-392 | |
| 14.x | 14.2.0-620 | |
| 13.x | 13.0.5-007 | |
| 13.x | 13.5.4-038 | |
| 14.x | 14.2.1-020 | |
| 14.x | 14.3.0-032 | |
| 15.x | 15.0.0-104 | |
| 15.x | 15.0.1-030 |
Is CVE-2026-76461 being exploited?
CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on 2026-09-14; U.S. federal agencies must remediate by 2026-09-17. Public exploit code is available.
How to fix CVE-2026-76461
- Follow Cisco’s advisory and implement any vendor-provided mitigations immediately.
- Restrict exposure: limit which systems can receive mail and block or quarantine suspicious inbound messages.
- Apply CISA KEV and BOD 26-04 remediation steps for affected assets and cloud services as applicable.
- Monitor SEG logs and forensics data for signs of exploit attempts and implement network segmentation to isolate affected appliances.
Frequently asked questions
Is CVE-2026-76461 being actively exploited?
CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog on 2026-09-14 and federal agencies were required to remediate by 2026-09-17; public exploit code is available.
Which Secure Email Gateway versions are affected by CVE-2026-76461?
Cisco Secure Email Gateway AsyncOS releases in the 13.x, 14.x and 15.x branches are listed as affected; examples from the vendor list include 13.0.0-392, 13.5.1-277, 14.0.0-698 and 15.0.0-104.
Is there a patch for CVE-2026-76461?
There is no fixed software version listed by the vendor in the provided data; follow Cisco’s advisory and apply recommended mitigations and compensating controls.
Does CVE-2026-76461 require authentication?
No, the vulnerability can be exploited by an unauthenticated remote attacker who can deliver a crafted email to the affected Cisco Secure Email Gateway.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76461
- cve.org/CVERecord?id=CVE-2026-76461
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026