If you run Cisco Secure Email Gateway — physical or virtual — and you haven't finished the vendor upgrade, today's the federal clock. CISA's Known Exploited Vulnerabilities due date for CVE-2026-76461 is 17 September 2026. That's not a soft reminder.
The bug is a critical SQL injection in email parsing on AsyncOS. An attacker sends a crafted message through the affected gateway. Bad SQL runs. From there the path Cisco and Rapid7 both describe ends in root command execution on the underlying operating system. No login required. No workaround published. Cisco put the advisory out on 14 September. CISA put the CVE on the KEV the same day.

Here's the shape of it. What the box does. What Cisco published. What's in scope and what isn't. Which builds close the hole. What "active exploitation" means in the PSIRT and Rapid7 notes — without turning this into a break-in guide. What CISA's KEV row and BOD 26-04 actually require of federal civilian agencies. The IoC greps Cisco already printed. What Rapid7 and the Cloud Security Alliance added on the 15th and 16th. One short colour section on a separate Cisco Identity Services Engine KEV that landed mid-week — that bug stays on its own shelf. Then the primary sources and a clean close.
What a Secure Email Gateway is doing in your path
Cisco Secure Email Gateway — the product line that used to sell as the IronPort Email Security Appliance, as Rapid7 reminds readers — sits where untrusted mail meets your organisation. It accepts messages from the open internet, inspects them, and decides what gets through. That job forces the box to parse content it didn't write and can't fully trust.
That's the architectural point CSA's research note leans on, and it's worth keeping plain. A perimeter mail appliance isn't a quiet internal database. It's a machine whose daily work is handling hostile input. When validation in that parsing path fails, the blast radius isn't "a bad row in a log." It's control of the appliance itself.
CVE-2026-76461 is tracked as CWE-89 — improper neutralization of special elements used in an SQL command. Cisco's advisory title is blunt: Cisco Secure Email Gateway SQL Injection Vulnerability. The path the vendors describe is crafted email carries malicious SQL through the affected device, then arbitrary SQL execution, then root command execution on the underlying OS. You don't need an account on the box for that shape. CVSS 3.1 base score 9.8, vector string AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Network reachable. Low attack complexity. No privileges. No user interaction. Confidentiality, integrity, and availability all High. Cisco's severity label: Critical. Workarounds: none.
The advisory clock — 14 September, then KEV the same day
Cisco Security Advisory cisco-sa-esa-inj-2bLVGmhX was first published 14 September 2026 at 16:00 GMT. That's the primary vendor document. Read it before you trust a secondary summary, including this one.
The same day, CISA added CVE-2026-76461 to the Known Exploited Vulnerabilities Catalog. The alert page is dated 14 September 2026: "CISA Adds One Known Exploited Vulnerability to Catalog." The KEV JSON entry for CVE-2026-76461, in the catalogVersion 2026.09.16 snapshot checked for this piece, carries dueDate 2026-09-17, forensicTriage Yes, and knownRansomwareCampaignUse Unknown. Binding Operational Directive 26-04 applies to federal civilian executive branch agencies. Required action language points at vendor instructions, BOD 26-04, and the forensics triage requirements that come with a Yes in that field.
So the federal story in one breath: disclosure Monday 14 September GMT afternoon, KEV the same day, remediation due Wednesday 17 September. The due date is today, not next week.
That three-day federal window isn't an invention of this paper. It's how KEV due dates land when CISA catalogs a vulnerability with a short fuse. Other pieces already cover the general "read the KEV feed" and "map your assets to the KEV" lanes. This one is the specific appliance, the specific CVE, and today's due date.

What is affected — and what Cisco says is not
Affected: Cisco Secure Email Gateway, physical and virtual, regardless of device configuration. That last clause matters. You don't get to argue that a particular feature toggle or deployment mode took you out of scope. Cisco's product statement is broad on the gateway line.
Confirmed not vulnerable, per the same advisory cluster: Cisco Secure Email and Web Manager; Cisco Secure Web Appliance. Don't mash those product names into the gateway CVE. Different boxes. Different risk. If your estate runs the manager or the web appliance beside an email gateway, inventory them separately and patch the gateway on its own clock.
Rapid7's Emerging Threats Research note dated 15 September 2026 repeats the same product frame and notes the former IronPort branding for readers who still have that name on asset sheets and purchase orders. Useful for search. Not a second vulnerability.
The fixed builds — three trains, one preferred landing
Cisco's fixed releases, as carried by the advisory and matched in Rapid7 and CSA tables:
If you're on 15.5 and earlier → move to 15.5.5-014.
If you're on 16.0 → move to 16.0.4-302.
If you're on 16.5 → move to 16.5.0-780.
Cisco strongly recommends migrating to 16.5.0-780. That's the vendor's preferred landing zone, not this paper's editorial preference. If your change window or certification path forces you onto a train-specific fix first, take the matching fixed build for your train, then plan the recommended migrate. Don't invent a fourth build number. Don't assume a neighbouring minor release is fine because it "feels close."
No workarounds. That sentence from Cisco is doing real work. There's no published "disable this feature and you're safe until Friday" path in the materials this piece is allowed to use. Upgrade is the remediation. For federal civilian agencies under BOD 26-04 and the KEV row, upgrade-plus-forensics-triage is the required action set, not a newsletter tip.
Cloud customers — Cisco already moved the fleet
Cisco Secure Email Cloud is a different operational picture. Cisco states it already upgraded all cloud devices to 16.5.0-780. Cisco also says it contacted cloud customers where malicious activity was detected.
Two practical notes fall out of that. First, if you're a cloud customer, the build race may already be over on Cisco's side — but "Cisco patched the cloud fleet" isn't the same sentence as "your tenant has a clean forensic bill of health." If Cisco contacted you about malicious activity, treat that as an incident thread, not a marketing email. Second, cloud admins without CLI access may not be able to independently run the on-box IoC greps Cisco published for appliance operators. That limitation is in the source cluster. Don't invent a cloud-side substitute grep this paper didn't verify. Push your Cisco account team and your own mail and firewall telemetry instead.
Exploitation — active before the advisory, found through a TAC case
Cisco PSIRT became aware of active exploitation in September 2026. Rapid7 frames that as pre-disclosure / zero-day relative to the public advisory. The discovery path Cisco describes isn't a bug-bounty write-up. It was found during resolution of a Cisco TAC support case. Somebody was already in trouble deep enough to open a ticket. The root cause analysis led to the vulnerability and to the exploitation awareness.
Rapid7's 15 September ETR is explicit on what it doesn't have: no public proof-of-concept at publication; no attribution. CSA's 16 September research note likewise doesn't hand you a named threat actor. Cisco, CISA, Rapid7, and CSA coverage reviewed for this piece carry no public threat-actor attribution. This paper won't invent one.
What "root on the mail gateway" means in operational English: the appliance that reads your inbound and outbound mail is under someone else's control at the operating-system level. Mail flow, quarantine, encryption policies, and the trust other systems place in that box are all in play. Because the access is root, Cisco also warns that attackers may remove or hide evidence on the device itself. That's why the IoC section below tells you to cross-check outside the box.
IoCs Cisco already put in the advisory
Cisco's published indicator guidance is narrow and useful. Review mail_logs for suspicious SQL. The example grep Cisco gives for operators with CLI is:
cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs]
Presence of matching lines may indicate malicious activity. That's Cisco's language — "may indicate," not a courtroom verdict from a single hit. Because root access lets an adversary tidy the local scene, Cisco's follow-on advice is to cross-check network and firewall logs for unexpected uploads or downloads from the appliance to external IP addresses. Look outside the box for the traffic the box may no longer confess.
I'm not going to expand that into a payload tutorial. No crafted-email recipe. No SQL gadget walkthrough. If you need forensic depth beyond the vendor's published greps, take it to your IR retainer and Cisco TAC. If you need a morning decision, stay with patch status, log review, outbound traffic review, and the federal due date if you're in that scope.
Advisory revision notes also mention Snort rules 67109 and 67110. If your detection stack consumes Cisco/Talos Snort coverage, confirm those signatures are present and alerting. Signatures aren't a substitute for the fixed AsyncOS build. They're an extra tripwire while you finish the upgrade — or a way to hunt retrospectively if your sensor was live.

What CISA's KEV row actually demands
For readers outside U.S. federal civilian agencies, the KEV due date is still a prioritisation signal — it's how the U.S. government says "this one is being used, move it up the queue." For FCEB agencies, BOD 26-04 and the catalog entry make it a compliance clock.
The fields that matter for this CVE in the catalogVersion 2026.09.16 entry: dueDate 2026-09-17; forensicTriage Yes; knownRansomwareCampaignUse Unknown. Forensic triage Yes means you don't get to patch and forget without asking whether the box was already used against you. Unknown ransomware use means nobody in that catalog field is claiming a ransomware campaign link — and nobody is clearing you of other misuse either. Absence of a ransomware flag isn't a safety certificate.
Required action references vendor instructions plus BOD 26-04 plus the forensics triage requirements. In practice that stacks as: apply Cisco's fixed release for your train (or the recommended 16.5.0-780 migrate), run the investigative steps your BOD and forensics guidance require, and document it. This paper isn't your agency's ATO paperwork. It's the public clock and the public vendor path.
Rapid7 — 15 September ETR, same facts, no PoC
Rapid7's Emerging Threat Research post on 15 September 2026 is titled around CVE-2026-76461 as a critical Cisco Secure Email Gateway vulnerability exploited in the wild. It aligns on fixed versions with Cisco. It notes the IronPort heritage name. It states there was no public PoC at publication. It offers no attribution.
Use Rapid7 as corroboration and as a cleaner "exploited in the wild / pre-disclosure" frame for readers who don't live inside Cisco advisory HTML. Don't treat it as a second, conflicting technical root cause. Where Rapid7 and Cisco agree — and they do on the build numbers and the criticality — print the agreement and move on.
CSA research note — 16 September, edge-appliance pattern
The Cloud Security Alliance labs research note dated 16 September 2026 restates the same CVE facts and then does something Cisco's advisory doesn't: it frames Secure Email Gateway as a perimeter appliance that must parse untrusted mail, and it compares the shape to other recent edge root zero-days — Cisco SD-WAN CVE-2026-20245 and the SonicWall SMA July 2026 pattern. Label that comparison as CSA analysis, not a Cisco claim. CSA's fixed-version table matches Cisco's. Good secondary. Different voice.
The analytical point is worth keeping without turning it into hype. Edge devices that terminate or inspect untrusted traffic keep showing up in KEV-class stories when parsing bugs go straight to root. Mail gateways, VPN concentrators, SD-WAN heads — different products, same ugly neighbourhood. This piece stays on the email gateway. The SD-WAN and SonicWall citations are pattern colour from CSA, not co-equal scoops for this story.
Same-week Cisco colour — ISE CVE-2026-76460, separate shelf
Don't mash this into the mail-gateway bug.
On 16 September 2026, CISA also added CVE-2026-76460 — Cisco Identity Services Engine, Incorrect Use of Privileged APIs, an authentication-bypass class issue — to the KEV. Due date for that one is 2026-09-19. Vendor advisory: cisco-sa-ISE-ABP-VNSW7Tn5. Different product. Different CVE. Different due date. Different remediation path.
Why mention it at all? Timeline colour for teams that saw "another Cisco KEV" in the same 72-hour window and wondered if it was the same fire. It isn't. If your Identity Services Engine estate is in scope for 76460, open that advisory on its own tab and run that clock to 19 September. Then come back to 76461 for the mail gateways that are due today.
What a first-time listener needs in order
One. Product: Cisco Secure Email Gateway (AsyncOS), physical and virtual, any configuration. Former name in the field: IronPort Email Security Appliance.
Two. Bug: CVE-2026-76461, CWE-89 SQL injection in email parsing. Crafted email → arbitrary SQL → root on the underlying OS. Unauthenticated. CVSS 9.8. Critical. No workarounds.
Three. Vendor advisory: cisco-sa-esa-inj-2bLVGmhX, first published 14 September 2026, 16:00 GMT.
Four. Not vulnerable: Secure Email and Web Manager; Secure Web Appliance.
Five. Fixed builds: 15.5.5-014; 16.0.4-302; 16.5.0-780. Cisco strongly recommends 16.5.0-780. Cloud fleet already on 16.5.0-780; Cisco contacted cloud customers where malicious activity was detected.
Six. Exploitation: Cisco PSIRT aware of active exploitation in September 2026, pre-disclosure per Rapid7; found during a TAC support-case resolution. No public PoC at Rapid7's publication. No public attribution in Cisco/CISA/Rapid7/CSA coverage reviewed.
Seven. CISA: KEV add 14 September 2026; dueDate 2026-09-17; forensicTriage Yes; knownRansomwareCampaignUse Unknown; BOD 26-04 for FCEB.
Eight. IoCs: review mail_logs for suspicious SQL; example grep for COPY.*TO PROGRAM in IronPort Text Mail Logs; cross-check network/firewall logs for unexpected appliance uploads/downloads because root can hide local evidence. Snort rules 67109–67110 in advisory revision notes.
Nine. Secondaries: Rapid7 ETR 15 September; CSA research note 16 September (edge-appliance pattern vs SD-WAN CVE-2026-20245 and SonicWall SMA July 2026 — CSA analysis label).
Ten. Separate Cisco KEV same week: CVE-2026-76460 ISE auth bypass, due 19 September, advisory cisco-sa-ISE-ABP-VNSW7Tn5 — not this bug.
What this paper is not claiming
This piece doesn't invent a public proof-of-concept. It doesn't invent a threat-actor name. It doesn't invent victim organisations. It doesn't invent a workaround Cisco said doesn't exist. It doesn't claim Secure Email and Web Manager or Secure Web Appliance are in scope for 76461. It doesn't weld CVE-2026-76460 into the same root cause. It doesn't invent a YouTube launch film — youtubeId stays unset because no official Cisco or CISA advisory trailer was found for this story.
It also doesn't re-scoop chromium-hit-the-kev, three-day-clocks-on-the-worst, apple-patched-the-neural-engine, stylesmuggler-poisoned-the-failed-payment, check-the-kev-feed-first, map-your-assets-to-the-kev, entra-was-already-mitigated, or seven-more-on-the-kev. Those pieces own their lanes. Today's news is the email gateway, this CVE, and today's federal due date.
Why root on the mail path hits harder than a boring CVSS chart
A 9.8 on a leaf laptop is bad. A 9.8 on the box that decides which messages enter your organisation is a different kind of bad. The gateway sees addresses, attachments, routing decisions, and often integrates with directory and archive systems downstream. Root on that host isn't "someone read one mailbox." It's control of a trust chokepoint.
CSA's framing — perimeter appliance forced to parse untrusted mail — is the sober version of that point. You can disagree with CSA's comparison set and still accept the parsing-trust problem. Cisco's own impact language already gets you to root command execution. You don't need adjectives on top.
For Australian operators: CISA's due date doesn't bind your company the way it binds a U.S. federal civilian agency. The exploitability facts don't care about the passport on your change ticket. If the gateway is still on an unfixed build, the crafted-email path Cisco described doesn't check whether you're inside BOD 26-04 before it runs. Patch priority is still a local risk call. The public evidence says treat it as urgent.
Cloud versus on-prem — two different mornings
On-prem and virtual appliance owners: you own the build number. Check it. Schedule the fixed release or the recommended migrate to 16.5.0-780. Run the mail_log review. Pull firewall and NetFlow-style logs around the appliance's interfaces for odd egress. If you have Snort/Talos coverage, confirm 67109 and 67110. If forensic triage is in your policy set — and for FCEB it's required on this KEV row — don't skip it because the upgrade window was painful.
Cloud customers: Cisco says the fleet is already on 16.5.0-780. Your morning is less about "can I download the image" and more about "did Cisco contact us," "what does our mail telemetry show," and "who can run investigative queries when we lack CLI." Don't assume silence equals clean. Don't assume a support ticket you haven't read is spam.
Mixed estates — some cloud, some on-prem gateways, plus a Secure Email and Web Manager — need an inventory pass that keeps product SKUs distinct. The manager is out of scope for this CVE per Cisco. The gateway is in. Mixing them in one "we patched email" checkbox is how organisations lie to themselves.
The TAC-origin detail without turning it into folklore
Vulnerabilities get found in a lot of ways: research labs, bug bounties, internal QA, customer crashes. This one, per Cisco's account, surfaced while TAC was resolving a support case. That detail does two honest jobs. It explains how PSIRT learned about active exploitation in September 2026. It also reminds you that production pain can precede the PDF advisory. Someone's mail environment was already weird enough to escalate.
What that detail doesn't do: name the customer. Name the actor. Hand you a timeline of every compromised host. Those absences are real. Rapid7's "no attribution" and "no public PoC" lines at publication sit in the same honest gap. Print the gap. Don't fill it with guesses.
How to read "knownRansomwareCampaignUse: Unknown"
KEV readers sometimes treat the ransomware field as the only urgency dial. Wrong dial for this row. Unknown means CISA isn't asserting ransomware campaign use in that catalog field. The same row still says the vulnerability is known exploited, still sets a 17 September due date, still flags forensic triage. Ransomware is one monetisation path among many. Root on a mail gateway is useful for espionage, business email compromise staging, lateral movement, and quiet persistence even when nobody is deploying a locker. Don't wait for the ransomware flag to flip before you patch.
Snort rules are tripwires, not the fix
Rules 67109 and 67110 show up in Cisco advisory revision notes. Good. Enable them if your pipeline can take them. Hunt with them if you have PCAP or IDS history spanning the pre-disclosure window. Then still upgrade AsyncOS. Detection signatures lag creative attackers, and a root-level occupant can change how traffic looks after the first day. The fixed build closes the parsing hole. The signature watches for a known pattern. Different jobs.
Overlap hygiene — what this piece leaves alone
Chromium KEV stories, Apple Neural Engine patches, StyleSmuggler's Magento chain, Entra mitigations, and the general "check the KEV feed / map assets to KEV / three-day clocks" explainers already live elsewhere. If you came here for a generic KEV literacy piece, you're in the wrong file. If you came here because your asset list says Cisco Secure Email Gateway and the due date is 17 September 2026, you're in the right one.
Primary sources
Cisco Security Advisory cisco-sa-esa-inj-2bLVGmhX — Cisco Secure Email Gateway SQL Injection Vulnerability (first published 14 September 2026, 16:00 GMT): https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
CISA alert — CISA Adds One Known Exploited Vulnerability to Catalog (14 September 2026): https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog
CISA KEV JSON entry CVE-2026-76461 (catalogVersion 2026.09.16) — dueDate 2026-09-17; forensicTriage Yes; knownRansomwareCampaignUse Unknown.
Rapid7 ETR (15 September 2026) — CVE-2026-76461 critical Cisco Secure Email Gateway vulnerability exploited in the wild: https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/
Cloud Security Alliance labs research note (16 September 2026) — Cisco Secure Email Gateway root RCE: https://labs.cloudsecurityalliance.org/research/csa-research-note-cisco-secure-email-gateway-root-rce-202609/
BOD 26-04 — Prioritizing Security Updates Based on Risk: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
Secondary same-week colour only — CISA KEV add for CVE-2026-76460 (Cisco ISE), dueDate 2026-09-19, advisory cisco-sa-ISE-ABP-VNSW7Tn5 — keep separate from this gateway story.
Bottom line
The mail gateway went root. Not as a metaphor. As the impact Cisco and the KEV row are describing for CVE-2026-76461 when a crafted message meets unfixed AsyncOS.
Advisory on the 14th. KEV on the 14th. Federal due date on the 17th — today. Fixed builds are published. Cloud is already on 16.5.0-780. On-prem and virtual owners still have to move. No workaround. No public actor name. No official trailer film to embed. Just a critical mail-path bug, active exploitation before the PDF, and a clock that doesn't care whether your change board liked the maintenance window.
If you only carry one cluster out, carry this. Unauthenticated SQL injection on Secure Email Gateway to root. Patch to the matching fixed release or prefer 16.5.0-780. Triage as if the box may already have been used. Keep the ISE KEV on its own due date. Cite Cisco first, then CISA, Rapid7, and CSA.





The paper
Comments
No notes on this story yet.
Sign in to comment