Cisco Patches Actively Exploited Zero-Day in Email Gateway
Security researchers confirmed that malicious actors have exploited a critical SQL injection flaw (CVE-2026-76461) to target Cisco Secure Gateway appliances.
Vulnerability Overview
The vulnerability was identified in September 2025, with the vendor’s Product Security Incident Response Team issuing indicators of compromise for affected organizations to investigate potential breaches.
Discovery and Identification
The flaw impacts Cisco AsyncOS Software versions 16.5, 16.0, and 15.5, along with earlier iterations, across on-premises physical and virtual Secure Gateway devices. It also affects the cloud-based Cisco Secure Cloud service, prompting direct outreach to customers with compromised devices.
Impact and Affected Systems
The vulnerability arises from inadequate validation in the parsing logic, enabling unauthenticated attackers to execute malicious SQL commands via crafted messages. This allows unauthorized command execution with root-level privileges on the underlying operating system.
Exploitation Method
Organizations using Cisco Secure Gateway are advised to scrutinize mail_logs for anomalous SQL activity. Any suspicious entries may signal exploitation. For clustered environments, administrators must review logs across all nodes. However, threat actors could leverage root access to erase evidence, as seen in prior incidents where adversaries used log-cleaning tools after deploying backdoors following zero-day exploits.
Mitigation and Recommendations
Cisco recommends cross-referencing network and firewall logs outside the affected device to detect irregularities, such as unexpected data transfers from the compromised appliance to external IP addresses.
Cisco’s Recommendations
To mitigate the risk, Cisco has updated all Secure Cloud devices to Release 16.5.0-780. Enterprises are urged to upgrade to one of the following fixed versions: 15.5.5-014, 16.0.4-302, or 16.5.0-780 (preferred). These releases include patches for additional critical vulnerabilities. Post-upgrade, security teams should scan logs for indicators of compromise. If detected, physical device users should contact Cisco Technical Assistance Center for support. Virtual environments require forensic analysis, deployment of a patched virtual machine, reconfiguration of the appliance, and renewal of credentials and cryptographic materials. Ongoing monitoring for irregular behavior is essential.
Upgrade and Post-Upgrade Steps
The US Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-76461 in its Known Exploited Vulnerabilities catalog, mandating federal civilian agencies to resolve the issue by September 17 and verify for signs of compromise.
