Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Secure Email Gateway SQL Injection Vulnerability

A serious security flaw exists in Cisco Secure Email Gateway devices that process emails. This flaw lets attackers send specially crafted emails containing harmful SQL commands, enabling them to take full control of the system with administrator privileges. Cisco has released software updates to fix this issue, but no other workarounds are available. Users should promptly apply these updates to protect their systems from potential attacks.

Published 14/9/2026, 4:00:00 pmVerified 15/9/2026, 12:27:12 amRevision 1
Cisco critical network security advisory visual

In plain language

What this advisory means

A serious security flaw exists in Cisco Secure Email Gateway devices that process emails. This flaw lets attackers send specially crafted emails containing harmful SQL commands, enabling them to take full control of the system with administrator privileges. Cisco has released software updates to fix this issue, but no other workarounds are available. Users should promptly apply these updates to protect their systems from potential attacks.

Technical explanation

How the issue affects the environment

Cisco Secure Email Gateway running AsyncOS software versions up to 15.5.x, 16.0.x, and 16.5.x suffer from an email parsing vulnerability due to insufficient input validation. Crafted email messages containing malicious SQL statements can exploit this flaw, allowing unauthenticated remote attackers to execute arbitrary SQL commands. Execution of these commands may escalate to arbitrary OS command execution with root privileges on the underlying system. The vulnerability is tracked as CVE-2026-76461 with a critical severity rating. Cisco has provided fixed AsyncOS releases (15.5.5-014, 16.0.4-302, and 16.5.0-780) to remediate this vulnerability. No workaround mitigations are known.

Operational impact

Why teams should care

If exploited, this vulnerability allows attackers to gain full root access on Cisco Secure Email Gateway devices. This could lead to unauthorized control over email traffic processing, data compromise, interruption of services, and possible further network infiltration. The severity of impact is critical, risking business data integrity and operational continuity. Immediate remediation is essential to maintain trust and compliance.

Immediate action

Administrators must upgrade affected Cisco Secure Email Gateway devices to one of the fixed AsyncOS software releases: 15.5.5-014, 16.0.4-302, or 16.5.0-780. The upgrade can be done via the web-based management interface or command-line interface following Cisco's documented procedures. Upgrading is required as no other workarounds exist to mitigate this vulnerability.

Affected and fixed releases

Affected versionsCisco AsyncOS for Secure Email Gateway versions 15.5 and earlier, 16.0 prior to 16.0.4-302, 16.5 prior to 16.5.0-780
Fixed versions15.5.5-014, 16.0.4-302, 16.5.0-780

Temporary risk reduction

Cisco has stated that no workarounds are available for this vulnerability. The only effective remediation is to upgrade to the fixed software provided by Cisco.

Evidence and validation checklist

  • Cisco official security advisory published 2026-09-14
  • Cisco AsyncOS fixed releases 15.5.5-014, 16.0.4-302, 16.5.0-780
  • Detected malicious SQL statements in device mail_logs indicating exploitation
  • Direct Cisco customer notifications regarding detected malicious activity
  • No workaround available; upgrade strongly recommended

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source
Cisco Secure Email Gateway SQL Injection | Advisory | QCS