Attackers use SQL injection emails to root Cisco gateways

Key points

Cisco warns attackers are exploiting a previously unknown flaw, CVE-2026-76461, rated 9.8 out of 10.0, to run arbitrary commands as root on Secure Email Gateway appliances.

Attackers use SQL injection emails to root Cisco gateways

Attackers use SQL injection emails to root Cisco gateways

Key points

  • Cisco warns attackers are exploiting a previously unknown flaw, CVE-2026-76461, rated 9.8 out of 10.0, to run arbitrary commands as root on Secure Email Gateway appliances.
  • No login is required, as crafted emails let attackers inject SQL statements that the gateway executes, and Cisco has already upgraded affected cloud devices to AsyncOS 16.5.0-780.
  • There are no workarounds, so Cisco is urging customers to upgrade to fixed versions after also disclosing four more 9.8-rated and one 7.5-rated vulnerability classes.




Attackers use SQL injection emails to root Cisco gateways










Networking giant Cisco said attackers were exploiting a previously unknown flaw in its Secure Email Gateway, using crafted messages to run arbitrary commands as root on the appliances.

The vulnerability, CVE-2026-76461, is rated at a CVSS 3.1 base score of 9.8 out of 10.0 and affects physical and virtual gateways regardless of how they are configured.

Attackers need no login and no access to the management interface, as they can exploit a flaw in the email parsing logic of the software on the devices, which does not sufficiently validate message content.

This lets an attacker to inject malicious structured query language (SQL) statements in an email and have the gateway execute them.

“A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system,” Cisco said in its advisory.

Cisco said its product security incident response team became aware of active exploitation in September, and that the flaw was found while resolving a Technical Assistance Center (TAC) support case.

The United States Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its list of known exploited vulnerabilities (KEV) catalogue. 

Cloud customers caught up

Cisco’s hosted Secure Email Cloud service was also affected by the bug.

The company said it had directly contacted cloud customers whose devices showed malicious activity, and that it had already upgraded all cloud devices to AsyncOS 16.5.0-780.

Many cloud customers cannot check for themselves, as Cisco noted that administrators without command-line access may be unable to examine the indicators of compromise.

For on-premises appliances, Cisco supplied a search term for mail logs, namely looking for the string COPY ... TO PROGRAM to check for malicious activity.

This is a PostgreSQL command that sends database output to an operating system program, which would explain how a database attack becomes a shell on the appliance. 

The company advised administrators to check firewall and network logs held outside the appliance for unexpected uploads to, or downloads from, external IP addresses.

Attackers successfully exploiting the vulnerability could remove or hide evidence of unauthorised access, as they have root privileges.

No workarounds, and a catch for 16.0 users

There are no workarounds for the flaw, and users are advised to upgrade to fixed versions such as  AsyncOS 15.5.5-014, 16.0.4-302 and 16.5.0-780, with Cisco recommending customers moving to the last version.

Alongside the zero-day, Cisco published a hardening advisory covering four more vulnerability classes rated 9.8 and a fifth rated 7.5, affecting both Secure Email Gateway and Secure Email and Web Manager.

Cisco said it was not aware of malicious use of those, apart from the exploited SQL injection flaw.

Secure Email and Web Manager customers need versions 15.5.5-006 or 16.5.0-429.

Cisco said the grouping was intended to help customers patch and streamline disclosure, but the advisories do not disclose how many individual flaws sit behind the five CVE identifiers.

The batch of bugs was uncovered through internal testing using existing processes “as well as frontier AI models,” Cisco said.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.