Cisco Secure Email SQLi zero-day exploited in wild
An unauthenticated SQL injection flaw in Cisco Secure Email Gateway is being actively exploited for root-level remote code execution and is now in CISA's KEV catalog.
Cisco Secure Email Gateway and Secure Email and Web Manager (formerly ESA/SMA) contain multiple vulnerabilities, the most severe being CVE-2026-76461, an unauthenticated SQL injection reachable via a crafted email message. Successful exploitation allows arbitrary SQL execution leading to command execution as root, fully compromising the appliance. Cisco has confirmed active exploitation and CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 14, 2026. The flaw is not conditional on any specific exposed feature or port, increasing its reach across deployments.
Five additional lower-severity vulnerabilities were disclosed alongside the critical SQLi: a path traversal flaw (CVE-2026-76440), an improper access control issue allowing authentication/authorization bypass (CVE-2026-76441), an improper resource lifetime bug enabling resource exhaustion, unsafe deserialization, or improper initialization (CVE-2026-20353), an improper neutralization vulnerability enabling command/SQL/code injection or XSS (CVE-2026-76443), and an input validation flaw allowing resource exhaustion via unbounded numeric input (CVE-2026-76442).
Affected products include Secure Email Gateway versions prior to 15.5.5-0141, 16.0.4-3021, and 16.5.0-780, and Secure Email and Web Manager versions prior to 15.5.5-006 and 16.5.0-429 (16.0 has no fixed release and requires migration to a supported branch). Defenders should prioritize patching internet-facing Secure Email Gateway/Manager appliances immediately given confirmed in-the-wild exploitation, monitor for anomalous SQL activity or unexpected root-level process execution on these appliances, and apply standard vulnerability management, network segmentation, and least-privilege controls as outlined by Cisco and MS-ISAC.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-secure-email-products-could-allow-for-remote-code-execution_2026-096
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free