<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild-d7uezr0jz" -->

---
title: CVE-2026-76461: Critical Cisco Secure Email Gateway...
description: Cisco disclosed CVE-2026-76461, a critical SQL injection vulnerability in AsyncOS Software for Cisco Secure Email Gateway, carrying a CVSS score of 9.8. The...
canonical: https://daily.dev/posts/cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild-d7uezr0jz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild | daily.dev
og:description: Cisco disclosed CVE-2026-76461, a critical SQL injection vulnerability in AsyncOS Software for Cisco Secure Email Gateway, carrying a CVSS score of 9.8. The...
og:url: https://daily.dev/posts/cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild-d7uezr0jz
og:image: https://api.daily.dev/og/posts/D7uezr0Jz.png
og:image:alt: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

**[Rapid7 Cybersecurity Blog](https://daily.dev/sources/rapid7-blog)** · 2 min read · 0 upvotes · 0 comments

## Summary

Cisco disclosed CVE-2026-76461, a critical SQL injection vulnerability in AsyncOS Software for Cisco Secure Email Gateway, carrying a CVSS score of 9.8. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges by sending a specially crafted email, requiring no authentication or admin access. CISA added it to the Known Exploited Vulnerabilities catalog the same day it was disclosed, indicating zero-day exploitation before public disclosure. Cisco has released fixed versions (15.5.5-014, 16.0.4-302, 16.5.0-780) and urges emergency patching outside normal cycles. No public proof-of-concept exploit or threat actor attribution exists yet.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild>

## Questions this post answers

### What is CVE-2026-76461 in Cisco Secure Email Gateway and how bad is it?

CVE-2026-76461 is a critical SQL injection vulnerability in Cisco AsyncOS Software for Cisco Secure Email Gateway with a CVSS v3.1 score of 9.8. It allows an unauthenticated remote attacker to execute arbitrary commands with root privileges simply by sending a specially crafted email through a vulnerable gateway, with no admin access or authentication required.

_Teams running Cisco email gateways can track fast-moving CVE disclosures like this one on daily.dev._

### Is CVE-2026-76461 being actively exploited and what should I do about it?

Yes, Cisco's PSIRT confirmed active exploitation as a zero-day before public disclosure on September 14, 2026, and CISA added it to the Known Exploited Vulnerabilities catalog the same day. Organizations should upgrade Cisco Secure Email Gateway on an emergency basis to fixed versions 15.5.5-014, 16.0.4-302, or 16.5.0-780 rather than relying on network monitoring alone.

_Security teams triaging exploited-in-the-wild CVEs can follow patch guidance updates via daily.dev._

### Which Cisco Secure Email Gateway versions fix CVE-2026-76461?

Cisco released fixed builds for each affected branch: 15.5.5-014 for 15.5 and earlier, 16.0.4-302 for 16.0, and 16.5.0-780 for 16.5, which Cisco also recommends as the latest overall version to migrate to. No public proof-of-concept exploit code was available at the time of disclosure.

_daily.dev helps admins planning emergency patch rollouts stay on top of vendor advisories._

---

Tags: [#security](https://daily.dev/tags/security), [#sql](https://daily.dev/tags/sql), [#cisco](https://daily.dev/tags/cisco)

[View this post on daily.dev](https://daily.dev/posts/cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild-d7uezr0jz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild","url":"https://daily.dev/posts/cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild-d7uezr0jz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild-d7uezr0jz"},"datePublished":"2026-09-15T12:47:26.064Z","dateModified":"2026-09-16T20:35:45.129Z","description":"Cisco disclosed CVE-2026-76461, a critical SQL injection vulnerability in AsyncOS Software for Cisco Secure Email Gateway, carrying a CVSS score of 9.8. The...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/403310fc83643451d0e643aaed18bd42?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/403310fc83643451d0e643aaed18bd42?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Rapid7 Cybersecurity Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Rapid7 Cybersecurity Blog","logo":"https://media.daily.dev/image/upload/logos/placeholder.jpg","url":"https://daily.dev/sources/rapid7-blog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild-d7uezr0jz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,sql,cisco","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Rapid7 Cybersecurity Blog","item":"https://daily.dev/sources/rapid7-blog"},{"@type":"ListItem","position":3,"name":"CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild-d7uezr0jz#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-76461 in Cisco Secure Email Gateway and how bad is it?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-76461 is a critical SQL injection vulnerability in Cisco AsyncOS Software for Cisco Secure Email Gateway with a CVSS v3.1 score of 9.8. It allows an unauthenticated remote attacker to execute arbitrary commands with root privileges simply by sending a specially crafted email through a vulnerable gateway, with no admin access or authentication required. Teams running Cisco email gateways can track fast-moving CVE disclosures like this one on daily.dev."}},{"@type":"Question","name":"Is CVE-2026-76461 being actively exploited and what should I do about it?","acceptedAnswer":{"@type":"Answer","text":"Yes, Cisco's PSIRT confirmed active exploitation as a zero-day before public disclosure on September 14, 2026, and CISA added it to the Known Exploited Vulnerabilities catalog the same day. Organizations should upgrade Cisco Secure Email Gateway on an emergency basis to fixed versions 15.5.5-014, 16.0.4-302, or 16.5.0-780 rather than relying on network monitoring alone. Security teams triaging exploited-in-the-wild CVEs can follow patch guidance updates via daily.dev."}},{"@type":"Question","name":"Which Cisco Secure Email Gateway versions fix CVE-2026-76461?","acceptedAnswer":{"@type":"Answer","text":"Cisco released fixed builds for each affected branch: 15.5.5-014 for 15.5 and earlier, 16.0.4-302 for 16.0, and 16.5.0-780 for 16.5, which Cisco also recommends as the latest overall version to migrate to. No public proof-of-concept exploit code was available at the time of disclosure. daily.dev helps admins planning emergency patch rollouts stay on top of vendor advisories."}}]}
```

