HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Remote Code Execution (CVE‑2026‑76461) in Cisco Secure Email Gateway Added to CISA KEV Catalog

Cisco Secure Email Gateway (both physical and virtual) contains a zero‑day parsing flaw (CVE‑2026‑76461) that lets unauthenticated attackers execute commands with root privileges. The vulnerability is already being exploited, prompting CISA to list it in its KEV catalog. Organizations must prove they have robust logging, patch‑management, and incident‑response controls to meet audit and regulatory expectations.

Verisq™ Intelligence · 📅 September 16, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Remote Code Execution (CVE‑2026‑76461) in Cisco Secure Email Gateway Added to CISA KEV Catalog

What It Is – Cisco disclosed a zero‑day vulnerability (CVE‑2026‑76461) in the AsyncOS email‑parsing component of Cisco Secure Email Gateway. The flaw allows an unauthenticated attacker to embed malicious SQL in a crafted email, leading to arbitrary command execution with root privileges.

Exploitability – Actively exploited in the wild; CISA has listed it in the Known Exploited Vulnerabilities (KEV) catalog. CVSS 9.8 (Critical).

Affected Products – Cisco Secure Email Gateway (both physical and virtual appliances), regardless of configuration. No known work‑arounds.

Why It Matters for Trust & Control Assurance

  • Logging & Monitoring – Detecting the malicious SQL pattern requires continuous collection and review of mail‑logs across every device in a cluster, providing audit‑ready evidence of attempted exploitation.
  • Patch Management Evidence – Demonstrating timely application of the vendor‑issued fix is a core control that satisfies multiple frameworks (e.g., NIST CSF 2.0 “Protect” function).
  • Incident‑Response Readiness – A documented playbook that outlines log‑review steps and containment actions shows due diligence to regulators and enterprise buyers.

Recommended Actions

  1. Apply Cisco’s emergency patch immediately on all Secure Email Gateway instances.
  2. Enable and centralize mail‑log collection; search for the “COPY … TO PROGRAM” SQL pattern on every node.
  3. Update your incident‑response run‑book to include the specific log‑review steps and containment procedures for this exploit.
  4. Validate that your change‑management and patch‑verification controls capture the remediation as evidence.

Source: Security Affairs – CISA adds Cisco Secure Email Gateway flaw to KEV catalog

📰 Original Source
https://securityaffairs.com/199156/security/u-s-cisa-adds-cisco-secure-email-gateway-flaw-to-its-known-exploited-vulnerabilities-catalog.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →