NEWS
Cisco Email Gateways Fall to a Second Root Email
Cisco Secure Email Gateway has a second unauthenticated root bug in under a year. CVE-2026-76461 is already exploited, with a September 17 federal deadline.
Cisco’s Secure Email Gateway can be seized as root by one crafted email, a 9.8 SQL injection already used in live attacks. The flaw, CVE-2026-76461, needs no login and no special setup, and Cisco says it has no workaround.
It is the second unauthenticated root hole in this product since a December 2025 campaign that planted a log-wiping tool on the same AsyncOS boxes.
A Crafted Message Is Enough for Root
The bug sits in how AsyncOS parses inbound mail, the job the appliance exists to do. Cisco’s Product Security Incident Response Team published the advisory on September 14, 2026, after finding the issue while closing a Technical Assistance Center support case. In September 2026 the same team confirmed attackers were already using it.
The weakness is CWE-89, classic SQL injection, caused by weak checks in the parsing logic. An attacker sends a crafted email with malicious SQL statements through a vulnerable gateway. If the parse hits, those statements run, and the jump from SQL to a shell is what yields root on the operating system underneath.
The execute commands with root privileges path needs no user click and no admin session. Cisco says physical and virtual Secure Email Gateway appliances are affected no matter how they are configured. Secure Email and Web Manager and Secure Web Appliance are not.
A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Cisco PSIRT, advisory cisco-sa-esa-inj-2bLVGmhX
Douglas McKee, director of vulnerability intelligence at Rapid7, said that in practical terms the attacker then controls the gateway itself. The hunt Cisco published is blunt: on the box, grep the mail_logs for COPY TO PROGRAM, a SQL form that can hand work to an operating-system program. That string is only an example. Cisco says it is not a full list.
Last Winter’s Campaign Already Wiped the Logs
Cisco became aware of the earlier campaign on December 10, 2025, again through a TAC case. Attacks had been running since at least late November 2025 against a limited set of appliances. The hole then was CVE-2025-20393, scored 10.0, in the Spam Quarantine web feature, not in the mail parser.
That campaign needed three things at once: a vulnerable AsyncOS build, Spam Quarantine turned on, and that Spam Quarantine reachable from the internet. Cisco’s own guides do not require that exposure, and the feature is off by default. Secure Email Cloud devices were not hit in that wave. This time the mail listener itself is the door, so those limits do not apply.
Cisco Talos tracked the 2025 actor as UAT-9686 and, with moderate confidence, called it a Chinese-nexus group whose tools overlap with clusters Talos also follows, including APT41 and UNC5174. After root, the group left AquaShell, a Python backdoor dropped into an existing web file at /data/web/euq_webui/htdocs/index.py, plus AquaTunnel and Chisel for covert paths in and out.
They also left an AquaPurge log-clearing utility that uses egrep to strip chosen keywords from log files and write the cleaned text back. Cisco later said the persistence could not be trusted as removed in place. A fixed build was required to clear it. On December 20, 2025, the Shadowserver Foundation counted 120 Cisco Secure Email Gateway and Secure Email and Web Manager devices likely open to that older bug, and over 650 fingerprinted appliances on the public internet.
THE TWO ROOT CAMPAIGNS
- Late November 2025: Attacks on CVE-2025-20393 begin against internet-facing Spam Quarantine.
- December 10, 2025: Cisco learns of the campaign while working a TAC case.
- December 17, 2025: Cisco publishes the campaign advisory and a 10.0 score; CISA adds the CVE to KEV with a December 24, 2025 due date.
- December 20, 2025: Shadowserver reports 120 likely vulnerable devices and over 650 fingerprinted.
- January 15, 2026: Cisco marks the 2025 advisory final as version 2.0.
- September 2026: PSIRT becomes aware that CVE-2026-76461 is being exploited.
- September 14, 2026: Cisco ships the SQL-injection advisory; CISA adds the new CVE to KEV.
- September 17, 2026: Federal civilian agencies face the listed remediation date.
Josh Picolet, vice president of detection and analysis at Team Cymru, later noted that this is only the second Secure Email Gateway flaw ever placed in that federal catalog, and that the repeat fits actors who treat edge appliances as durable access rather than a one-off smash.
Cloud Boxes Are Patched, On-Prem Ones Are Not
Cisco has already moved every Secure Email Cloud device to AsyncOS 16.5.0-780, the build it wants everyone else on. It also ran a threat-intel pass on that cloud fleet and directly contacted customers whose devices showed signs of possible compromise. Those customers are still told to renew credentials and cryptographic material on the appliance. Cloud admins without CLI access cannot run the mail_logs grep themselves.
Anyone running their own hardware or virtual machine has to pick a fixed train and push it. Cisco’s table is short, and the company is explicit that workarounds do not exist.
FIXED ASYNCOS RELEASES
| AsyncOS train | First fixed build | Cisco’s note |
|---|---|---|
| 15.5 and earlier | 15.5.5-014 | Upgrade path for older trains |
| 16.0 | 16.0.4-302 | Stay on 16.0 only if you must |
| 16.5 | 16.5.0-780 | Recommended target; already on all Secure Email Cloud devices |
The upgrade can run from System Administration, then System Upgrade, or from the CLI with upgrade and DOWNLOADINSTALL. After the install, the box reboots. As of Monday, September 14, 2026, Shadowserver was still tracking more than 400 Cisco Secure Email Gateway appliances on the public internet. That figure does not say how many are honeypots or already patched. It does say the listening pool is not small.
Why Empty Mail Logs Do Not Clear a Box
Cisco’s own note on evidence is the part that should change how teams hunt. Root on the appliance means the people who got in can delete or hide the traces on that same disk. A clean grep is not a clean box. The company tells admins to read network and firewall logs off the gateway, looking for odd uploads from the device to outside addresses or downloads from hostile ones.
THE HUNT CISCO WANTS RUN
- Mail logs: Search mail_logs on every cluster member for suspicious SQL, including COPY TO PROGRAM.
- Off-box logs: Compare firewall and network records for unexpected transfers to or from the gateway.
- Cloud fleet: Wait for Cisco’s contact if you lack CLI; the vendor says it already reached customers with hits.
- Physical hardware: If compromise looks likely, call TAC and turn on the remote-access path Cisco asks for.
- Virtual machines: Keep forensic images first, then deploy a new VM on a fixed build, rebuild the config, and renew credentials and crypto.
That virtual rebuild is not a tidy patch. Cisco warns that standing up a new instance destroys configs and logs on the old one, which is why the snapshot has to come first. Keep watching the new machine for odd behavior. If the device is still on an affected build and nobody has a reason to think it was hit, Cisco still wants the upgrade done.
Hardening around the patch is the same list Cisco has been repeating since the 2025 campaign: keep management off the open internet, split mail and management onto separate interfaces, send logs to an external server and keep them long enough to investigate, shut HTTP on the admin portal, and drop services you do not need, including FTP.
Federal Agencies Have Until September 17
CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 14, 2026, the same day Cisco’s advisory went out. Federal civilian agencies have until September 17 to remediate. Binding Operational Directive 26-04 tells those agencies to move first on KEV items that sit on public assets and give an attacker full control after a hit, and to check whether someone was already inside before the patch landed.
Cisco has not said who is exploiting the new bug, how long the attacks have run, or how many organizations are in the set. The cloud contacts are the only victim signal it has put on paper, and even that is uncounted. Picolet’s point about reusable edge access is the frame that still fits: a mail gateway that reads every message is a foothold worth keeping, and a log wiper is how you keep it.
WHAT WE KNOW
- The bug: Unauthenticated SQL injection in AsyncOS email parsing, scored 9.8, no workaround.
- The fix: 15.5.5-014, 16.0.4-302, or 16.5.0-780, with cloud already on the last of those.
- The hunt: SQL in mail_logs, plus off-box firewall records, because local logs can be edited after root.
WHAT IS UNCONFIRMED
- The actor: Cisco has not attributed the September 2026 attacks.
- The scale: No public count of compromised organizations, on-prem or cloud.
- The dwell: PSIRT learned of abuse in September 2026; start date and persistence toolkit are unpublished.
Agencies that only install the build and skip the compromise check will have followed half of what CISA asked for. The other half is the same lesson the AquaPurge toolkit already taught.
The Mail Parser Still Shares Root
A gateway has to inspect mail before it knows whether that mail is hostile. If that parser runs with root rights on the same host that holds keys, queues, and every inbound message, a parse bug is a takeover. That is the design the 2025 campaign used through Spam Quarantine, and it is the design this SQL injection uses through the listener itself.
A root-level, unauthenticated RCE in an email gateway is about as good a foothold as an attacker gets.
Josh Picolet, vice president of detection and analysis, Team Cymru
McKee called the mix ugly for the same reasons: no login, reach by sending mail, root at the end, and confirmed abuse. Operators who still have a 15.x or 16.0 box in the path should treat 16.5.0-780 as the destination and treat a quiet local log as incomplete evidence. Cisco has not named the group behind the September attacks, or said how many organizations were hit. On a physical appliance that looks dirty, the next call is TAC. On a virtual one, the next step is a new machine, a rebuilt config, and new keys, because the old image is no longer a source of truth.
-
NEWS2 months agoRune Bets on Hillerød for His Achilles Comeback
-
NEWS1 month agoPermafrost Thaw Runs Fastest in Mountains, Not Arctic Soils
-
AUTO1 month agoThe Last Manual V-12 Lamborghini Cannot Come to America
-
NEWS1 month agoThe Roman Space Telescope Flies After Four Budget Fights
-
BUSINESS1 month agoSoftware Stocks Rally as Underweight Funds Face Dreamforce
-
NEWS1 month agoDallas Judge Blocks the SEC Ban, Coaches Still Face Fines
-
BUSINESS1 month agoInfluencer Investors Trade Cash Fees for Illiquid Equity
-
BUSINESS2 months agoRubicon Research Q1 Tests Its Specialty Pharma Bet
