Full Report
Cisco security advisory (AV26-921)
Analysis Summary
# Vulnerability: Cisco Secure Email Gateway SQL Injection
## CVE Details
- **CVE ID:** CVE-2026-76461
- **CVSS Score:** Not explicitly listed in the provided text (Note: SQL injection in security gateways typically results in High/Critical scores).
- **CWE:** CWE-89 (Improper Neutralization of Special Elements used in an SQL Command)
## Affected Systems
- **Products:**
- Cisco AsyncOS for Cisco Secure Email Gateway
- Cisco Secure Email Gateway
- Cisco Secure Email and Web Manager
- **Versions:**
- AsyncOS: Prior to 15.5.5-014, 16.0.4-302, and 16.5.0-780
- Secure Email Gateway: Prior to 15.5.5-014 and 16.5.0-780
- Secure Email and Web Manager: Prior to 15.5.5-006 and 16.5.0-429
- **Configurations:** Systems running vulnerable versions of Cisco AsyncOS are susceptible.
## Vulnerability Description
The vulnerability is a SQL injection flaw located within the web-based management interface or processing components of Cisco Secure Email Gateway products. An attacker could exploit this by sending specially crafted input to the affected system, allowing them to execute arbitrary SQL commands. This can lead to unauthorized access to sensitive data, modification of system configurations, or potential bypass of authentication mechanisms.
## Exploitation
- **Status:** **Exploited in the wild.** Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog on September 14, 2026.
- **Complexity:** Low (Standard SQL injection techniques).
- **Attack Vector:** Network (Remote exploitation possible).
## Impact
- **Confidentiality:** High (Access to sensitive email metadata, user information, and system logs).
- **Integrity:** High (Ability to modify security policies and database records).
- **Availability:** Medium/High (Potential for database corruption or service disruption).
## Remediation
### Patches
Cisco has released the following security updates to address this flaw:
- **Cisco AsyncOS/Secure Email Gateway:** Update to 15.5.5-014, 16.0.4-302, or 16.5.0-780 (or later).
- **Cisco Secure Email and Web Manager:** Update to 15.5.5-006 or 16.5.0-429 (or later).
### Workarounds
- No specific workarounds are provided in the advisory. Users are strongly urged to apply the patches immediately due to active exploitation.
## Detection
- **Indicators of Compromise:** Monitor web management logs for unusual SQL syntax or unauthorized access attempts.
- **Detection methods and tools:** Organizations should utilize vulnerability scanners to identify outdated AsyncOS versions. Refer to CISA KEV guidelines for scanning internal networks for this specific CVE.
## References
- **Vendor Advisory:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
- **Hardening Guide:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
- **CISA KEV Catalog:** hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461
- **Cisco Security Publication Listing:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/publicationListing[.]x