Cisco Secure Email Gateway CVE-2026-76461: Root by Email, Due Sep 17
A single crafted email is enough. Cisco's advisory cisco-sa-esa-inj-2bLVGmhX, published on the day CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog, September 14, 2026, describes a SQL injection in the email parsing of AsyncOS for Cisco Secure Email Gateway. In Cisco's words, an unauthenticated, remote attacker sends a message containing malicious SQL statements through the appliance and ends up executing commands "with root privileges on the underlying operating system". CVSS 9.8. No workarounds. Physical and virtual appliances alike, regardless of configuration. Cisco's PSIRT became aware of active exploitation in September; the flaw was found while resolving a support case, which is to say a customer was already hit.
What Cisco fixed, and the row that is missing
Cisco's fixed-release table has three rows. The lifecycle column is from Cisco's Software Lifecycle Support Statement as we serve it on the Secure Email Gateway page, where "security support" is Cisco's End of Vulnerability and Security Support milestone.
| AsyncOS train | First fixed release | End of software maintenance | End of security support |
|---|---|---|---|
| 16.5 | 16.5.0-780 (Cisco's recommended release) | August 30, 2027 | August 30, 2029 |
| 16.0 | 16.0.4-302 | October 30, 2025 | October 30, 2027 |
| 15.5 | 15.5.5-014 (the row reads "15.5 and earlier") | October 30, 2026 | April 30, 2027 |
| 15.0 | None; upgrade to 15.5.5-014 | October 30, 2025 | April 30, 2027 |
| 14.3, 14.2, 14.0, 13.5, 13.0 | None; upgrade to 15.5.5-014 | Not in Cisco's table | Not in Cisco's table |
Read the 15.0 row twice. On Cisco's lifecycle statement, 15.0 is a FIPS-compliant train whose software maintenance ended on October 30, 2025 and whose vulnerability and security support runs to April 30, 2027. By the statement's own definition, that milestone is "the last date that Cisco engineering may release a software maintenance release or scheduled software remedy for a security vulnerability concern". The advisory ships no 15.0 remedy. Its path for 15.0 is the same as for 14.x: move to 15.5.5-014. "May release" is not "will release", and this is what the difference looks like on the day it matters.
The older trains are a different case. Cisco's CVE record names 13.0, 13.5, 14.0, 14.2 and 14.3 releases as affected, and its lifecycle statement begins at 15.0: there is no published support window for anything older, so there is no milestone to be inside or outside of. They are affected, unfixed on their own lines, and undocumented. The upgrade to 15.5.5-014 is the only route Cisco offers, and 15.5 is itself a FIPS train that leaves software maintenance on October 30, 2026.
What to do, by train
16.5, 16.0, 15.5: apply the fixed release from the table through System Administration, System Upgrade, ahead of September 17 if you are a federal agency and this week regardless. Then read the mail logs for SQL statements before you call the appliance clean; Cisco's advisory is explicit that a hit means TAC, not a reboot.
15.0: there is nothing to apply on your train. The upgrade to 15.5.5-014 is the fix, and it lands you on a train whose own security support ends on April 30, 2027. Plan the next hop to 16.5 in the same change window if you can: its security support runs to August 30, 2029.
14.x or older: the same upgrade, sooner, and with the triage first. An appliance on a train Cisco no longer documents has been receiving nothing for a long time; assume the mail logs are the only record you have.
Secure Email Cloud: Cisco says it upgraded all cloud devices to 16.5.0-780 and contacted the customers where indicators of compromise were found. If you were not contacted, that is Cisco's statement that nothing was found on your tenant, not that nothing was tried.
Frequently Asked Questions
Which Cisco Secure Email Gateway versions have a fix for CVE-2026-76461?
Cisco's advisory lists three first fixed releases: 15.5.5-014 for 15.5 and earlier, 16.0.4-302 for 16.0, and 16.5.0-780 for 16.5, which Cisco recommends. There is no 15.0 build; a 15.0 appliance upgrades to 15.5.5-014 or later. Cisco's cloud-hosted Secure Email Cloud was upgraded by Cisco to 16.5.0-780.
What is CISA's deadline for CVE-2026-76461?
CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 14, 2026 with a due date of September 17, 2026 for federal agencies, and marked it as requiring forensic triage under BOD 26-04, meaning agencies must check the appliance for compromise, not only patch it.
Is AsyncOS 15.0 still supported?
By Cisco's Software Lifecycle Support Statement, 15.0 passed End of Software Maintenance on October 30, 2025 and remains inside End of Vulnerability and Security Support until April 30, 2027. Even so, Cisco's advisory ships no 15.0 build for CVE-2026-76461; the fix for a 15.0 appliance is the upgrade to 15.5.5-014.
What about AsyncOS 14.x and older?
Cisco's own CVE record lists 13.0, 13.5, 14.0, 14.2 and 14.3 releases as affected, and Cisco's lifecycle statement carries no support dates for any train before 15.0. The advisory's only path for them is the "15.5 and earlier" row: upgrade to 15.5.5-014. There is no fixed build on those lines and no support window Cisco publishes for them.
Related
- Cisco Secure Email Gateway — every AsyncOS train Cisco publishes dates for, with its three milestones
- Cisco FMC CVE-2026-20079 — the same week's other Cisco listing, and the same lifecycle question from a train past its milestone
- EOS Edge Device List — every edge platform we track with a CISA KEV history
- Exploited & Unpatchable — the feed of KEV entries on products past their fix window
- How we verify our dates — the rules every number on this site is held to