endoflife.ai
Cisco Secure Email Gateway EOS Edge Device List Exploited & Unpatchable EOL Watch

Cisco Secure Email Gateway CVE-2026-76461: Root by Email, Due Sep 17

By Scott Bissett  ·  Published: September 14, 2026  ·  EOL Watch — news analysis  ·  Read at Cisco's advisory, Cisco's CVE record and CISA's catalog on the day of listing; lifecycle dates from Cisco's Secure Email Gateway Software Lifecycle Support Statement.

A single crafted email is enough. Cisco's advisory cisco-sa-esa-inj-2bLVGmhX, published on the day CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog, September 14, 2026, describes a SQL injection in the email parsing of AsyncOS for Cisco Secure Email Gateway. In Cisco's words, an unauthenticated, remote attacker sends a message containing malicious SQL statements through the appliance and ends up executing commands "with root privileges on the underlying operating system". CVSS 9.8. No workarounds. Physical and virtual appliances alike, regardless of configuration. Cisco's PSIRT became aware of active exploitation in September; the flaw was found while resolving a support case, which is to say a customer was already hit.

The deadline and the extra requirement. CISA's due date for federal agencies is September 17, 2026, three days after listing. The entry also carries a forensic-triage flag under CISA's Binding Operational Directive 26-04: patching alone does not close it. Cisco's own indicator of compromise is the appliance's mail logs, where an exploit attempt appears as suspicious SQL statements; the advisory tells anyone who finds one to contact TAC before trusting the box. An email gateway holds every message that crossed it and the credentials it uses to relay; a root shell there is not one appliance lost.
Quick answer: Cisco Secure Email Gateway 16.5 is supported until August 30, 2029, its end-of-support date. Active support for Cisco Secure Email Gateway 16.5 ends on August 30, 2027; security fixes continue until that end-of-life date. The next Cisco Secure Email Gateway version to reach end of life is 15.5 (FIPS compliant), on April 30, 2027. Every Cisco Secure Email Gateway version's release and end-of-support date is on the Cisco Secure Email Gateway lifecycle page.

What Cisco fixed, and the row that is missing

Cisco's fixed-release table has three rows. The lifecycle column is from Cisco's Software Lifecycle Support Statement as we serve it on the Secure Email Gateway page, where "security support" is Cisco's End of Vulnerability and Security Support milestone.

AsyncOS trainFirst fixed releaseEnd of software maintenanceEnd of security support
16.516.5.0-780 (Cisco's recommended release)August 30, 2027August 30, 2029
16.016.0.4-302October 30, 2025October 30, 2027
15.515.5.5-014 (the row reads "15.5 and earlier")October 30, 2026April 30, 2027
15.0None; upgrade to 15.5.5-014October 30, 2025April 30, 2027
14.3, 14.2, 14.0, 13.5, 13.0None; upgrade to 15.5.5-014Not in Cisco's tableNot in Cisco's table

Read the 15.0 row twice. On Cisco's lifecycle statement, 15.0 is a FIPS-compliant train whose software maintenance ended on October 30, 2025 and whose vulnerability and security support runs to April 30, 2027. By the statement's own definition, that milestone is "the last date that Cisco engineering may release a software maintenance release or scheduled software remedy for a security vulnerability concern". The advisory ships no 15.0 remedy. Its path for 15.0 is the same as for 14.x: move to 15.5.5-014. "May release" is not "will release", and this is what the difference looks like on the day it matters.

The older trains are a different case. Cisco's CVE record names 13.0, 13.5, 14.0, 14.2 and 14.3 releases as affected, and its lifecycle statement begins at 15.0: there is no published support window for anything older, so there is no milestone to be inside or outside of. They are affected, unfixed on their own lines, and undocumented. The upgrade to 15.5.5-014 is the only route Cisco offers, and 15.5 is itself a FIPS train that leaves software maintenance on October 30, 2026.

What we are not saying. We are not saying 15.0 is unsupported; Cisco's statement says the opposite until April 2027. We are saying that the security-support milestone did not produce a 15.0 build for the one flaw that is being exploited, which is the fact a 15.0 operator needs this week. We are also not listing 14.x and older on our Exploited & Unpatchable feed yet: they meet the affected and no-fixed-build tests, but Cisco publishes no end-of-support date for them, and that feed does not infer one.
Running Cisco Secure Email Gateway past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Cisco Secure Email Gateway is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

What to do, by train

16.5, 16.0, 15.5: apply the fixed release from the table through System Administration, System Upgrade, ahead of September 17 if you are a federal agency and this week regardless. Then read the mail logs for SQL statements before you call the appliance clean; Cisco's advisory is explicit that a hit means TAC, not a reboot.

15.0: there is nothing to apply on your train. The upgrade to 15.5.5-014 is the fix, and it lands you on a train whose own security support ends on April 30, 2027. Plan the next hop to 16.5 in the same change window if you can: its security support runs to August 30, 2029.

14.x or older: the same upgrade, sooner, and with the triage first. An appliance on a train Cisco no longer documents has been receiving nothing for a long time; assume the mail logs are the only record you have.

Secure Email Cloud: Cisco says it upgraded all cloud devices to 16.5.0-780 and contacted the customers where indicators of compromise were found. If you were not contacted, that is Cisco's statement that nothing was found on your tenant, not that nothing was tried.

Frequently Asked Questions

Which Cisco Secure Email Gateway versions have a fix for CVE-2026-76461?

Cisco's advisory lists three first fixed releases: 15.5.5-014 for 15.5 and earlier, 16.0.4-302 for 16.0, and 16.5.0-780 for 16.5, which Cisco recommends. There is no 15.0 build; a 15.0 appliance upgrades to 15.5.5-014 or later. Cisco's cloud-hosted Secure Email Cloud was upgraded by Cisco to 16.5.0-780.

What is CISA's deadline for CVE-2026-76461?

CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 14, 2026 with a due date of September 17, 2026 for federal agencies, and marked it as requiring forensic triage under BOD 26-04, meaning agencies must check the appliance for compromise, not only patch it.

Is AsyncOS 15.0 still supported?

By Cisco's Software Lifecycle Support Statement, 15.0 passed End of Software Maintenance on October 30, 2025 and remains inside End of Vulnerability and Security Support until April 30, 2027. Even so, Cisco's advisory ships no 15.0 build for CVE-2026-76461; the fix for a 15.0 appliance is the upgrade to 15.5.5-014.

What about AsyncOS 14.x and older?

Cisco's own CVE record lists 13.0, 13.5, 14.0, 14.2 and 14.3 releases as affected, and Cisco's lifecycle statement carries no support dates for any train before 15.0. The advisory's only path for them is the "15.5 and earlier" row: upgrade to 15.5.5-014. There is no fixed build on those lines and no support window Cisco publishes for them.

Related

© 2026 endoflife.ai · How we verify our dates · API · About