← Back to blog
Blog Detail

CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Added to CISA KEV

CISA added CVE-2026-76461, a SQL injection in Cisco Secure Email Gateway (AsyncOS), to the KEV catalog on 2026-09-14 with a 2026-09-17 due date. Patch or mitigate now and verify exposure.

Trusteed Team
Trusteed Editorial
Written On
Sep 22, 2026
Category
KEV
Read Time
4 min read
  • CVE-2026-76461
  • KEV
  • CISA
  • Cisco
  • Secure Email Gateway
  • AsyncOS
  • SQL Injection
  • CWE-89
  • BOD 26-04
CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Added to CISA KEV

CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Added to CISA KEV

TL;DR

CISA added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway (AsyncOS), to the Known Exploited Vulnerabilities catalog on 2026-09-14, with a remediation due date of 2026-09-17. If you run Cisco Secure Email Gateway, inventory internet-facing instances today, apply Cisco's mitigations or updates per the vendor advisory, and confirm BOD 26-04 compliance.

What is this vulnerability?

  • CVE ID: CVE-2026-76461
  • Vendor / product: Cisco / Secure Email Gateway (AsyncOS)
  • Vulnerability name: Cisco Secure Email Gateway SQL Injection Vulnerability
  • Weakness: CWE-89 (SQL Injection)
  • Impact: An unauthenticated, remote attacker could execute arbitrary commands with root privileges on the underlying operating system.
  • CISA KEV status: Yes — added 2026-09-14
  • CISA due date: 2026-09-17
  • Known ransomware use: Unknown

Cisco Secure Email Gateway is commonly deployed at the network edge to inspect and filter inbound and outbound mail. That placement makes exposure assessment and rapid remediation a priority for defenders.

KEV vs CVSS vs EPSS

Signal What it measures How to use it for this CVE
CISA KEV Confirmed exploitation in the wild, with a binding remediation due date for federal agencies Treat as actively exploited. Prioritize CVE-2026-76461 ahead of routine patching and meet the 2026-09-17 due date.
CVSS Technical severity of the vulnerability Use the vendor advisory and NVD entry to understand severity and preconditions; do not let a severity score delay action on a KEV-listed CVE.
EPSS Probability of exploitation in the near term Useful for ranking non-KEV items; for this CVE, KEV status already establishes urgency.

Step-by-step remediation

  1. Inventory. Identify all Cisco Secure Email Gateway (AsyncOS) deployments, including on-premises, hybrid, and cloud-hosted instances. Note which are internet-facing or otherwise reachable by untrusted networks.
  2. Patch or mitigate. Apply the mitigations and updates described in Cisco's security advisory for CVE-2026-76461. Follow CISA's BOD 26-04 guidance for prioritizing security updates based on risk. If mitigations are unavailable for a given deployment, follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product.
  3. Verify. Confirm the fix is in place on every instance, validate that the vulnerable path is no longer reachable, and review logs for signs of exploitation. Apply CISA's Forensics Triage Requirements as directed.
  4. Ticket closure. Document the asset, the action taken, the verification evidence, and the completion date. Close the remediation ticket only after verification, and record the KEV due date of 2026-09-17 in your tracking system.

FAQ

Is CVE-2026-76461 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-14.

What is the CISA due date for CVE-2026-76461? The due date is 2026-09-17. Federal agencies and other covered organizations should complete remediation by that date.

Is Cisco Secure Email Gateway internet-facing? It is frequently deployed at the network edge to process email, so many instances are reachable from untrusted networks. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Is there a ransomware tie to CVE-2026-76461? Known ransomware use is currently unknown. Because the CVE is KEV-listed, treat it as actively exploited and prioritize accordingly.

What is the weakness type? CWE-89, SQL Injection. An unauthenticated, remote attacker could execute arbitrary commands with root privileges on the underlying operating system.

Related resources

Join Our Newsletter

Trusteed keeps you informed: emerging risks, platform updates, and practical guides for faster defense.