Critical Remote Code Execution (CVE‑2026‑76461) in Cisco Secure Email Gateway Added to CISA KEV Catalog
What It Is – Cisco disclosed a zero‑day vulnerability (CVE‑2026‑76461) in the AsyncOS email‑parsing component of Cisco Secure Email Gateway. The flaw allows an unauthenticated attacker to embed malicious SQL in a crafted email, leading to arbitrary command execution with root privileges.
Exploitability – Actively exploited in the wild; CISA has listed it in the Known Exploited Vulnerabilities (KEV) catalog. CVSS 9.8 (Critical).
Affected Products – Cisco Secure Email Gateway (both physical and virtual appliances), regardless of configuration. No known work‑arounds.
Why It Matters for Trust & Control Assurance
- Logging & Monitoring – Detecting the malicious SQL pattern requires continuous collection and review of mail‑logs across every device in a cluster, providing audit‑ready evidence of attempted exploitation.
- Patch Management Evidence – Demonstrating timely application of the vendor‑issued fix is a core control that satisfies multiple frameworks (e.g., NIST CSF 2.0 “Protect” function).
- Incident‑Response Readiness – A documented playbook that outlines log‑review steps and containment actions shows due diligence to regulators and enterprise buyers.
Recommended Actions
- Apply Cisco’s emergency patch immediately on all Secure Email Gateway instances.
- Enable and centralize mail‑log collection; search for the “COPY … TO PROGRAM” SQL pattern on every node.
- Update your incident‑response run‑book to include the specific log‑review steps and containment procedures for this exploit.
- Validate that your change‑management and patch‑verification controls capture the remediation as evidence.
Source: Security Affairs – CISA adds Cisco Secure Email Gateway flaw to KEV catalog