CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog
CISA Adds Actively Exploited Cisco Secure Email Gateway SQL (TL-2026-2508) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-14 and last reviewed 2026-09-15. It is attributed to UAT-9686 (China) with medium confidence, affects Cisco Secure Email Gateway (AsyncOS Software), references 1 CVE (CVE-2026-76461), maps to 22 MITRE ATT&CK techniques (T1005, T1021.004, T1027), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-2508
- Threat ID
- TL-2026-2508
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-14
- Last reviewed
- 2026-09-15
- Attribution
- UAT-9686
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, critical infrastructure, telecoms
- Target regions
- Southeast Asia, taiwan
- Detection rules
- 9
- Indicators of compromise
- 17
- Updates
- 2026-09-15 · 2 updates · revalidated 2× · latest source
Malware and tooling in CISA Adds Actively Exploited Cisco Secure Email Gateway SQL
Malware and tooling: AquaPurge, AquaShell, AquaTunnel, Chisel, ReverseSSH
CISA added CVE-2026-76461, a critical (CVSS 9.8) SQL injection in Cisco AsyncOS for Secure Email Gateway, to its KEV Catalog on September 14, 2026 after confirming active exploitation; an unauthenticated attacker can trigger the flaw with a crafted email to gain root-level command execution on the appliance. FCEB remediation is due September 17, 2026 under BOD 26-04.
How CISA Adds Actively Exploited Cisco Secure Email Gateway SQL works
CVE-2026-76461 is a SQL injection vulnerability (CWE-89) in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway (formerly the Cisco Email Security Appliance). Insufficient validation of email content allows an unauthenticated, remote attacker to send a specially crafted email containing malicious SQL statements to an affected device; the injected SQL is used to execute arbitrary operating-system commands with root privileges on the underlying appliance, giving the attacker full control with no authentication and no user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, 9.8/CRITICAL). Cisco Secure Email and Web Manager and Cisco Secure Web Appliance are not affected by this specific CVE. Cisco published advisory cisco-sa-esa-inj-2bLVGmhX and confirmed evidence of active, in-the-wild exploitation; CISA added the CVE to its Known Exploited Vulnerabilities Catalog the same day (September 14, 2026), triggering a Binding Operational Directive 26-04 remediation deadline of September 17, 2026 for U.S. Federal Civilian Executive Branch agencies, including a requirement to verify whether internet-exposed systems were compromised prior to patching. No workaround exists; Cisco's fixed releases are AsyncOS 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 (Cisco recommends migrating to 16.5.0-780). Cisco Cloud-hosted Secure Email instances were already patched by the vendor.
This disclosure follows a documented pattern of exploitation against the same appliance family. Cisco Talos assesses with MODERATE confidence that a China-nexus threat actor it tracks as UAT-9686 has been exploiting Cisco Secure Email Gateway and Secure Email and Web Manager appliances since at least late November 2025, publicly disclosed December 10, 2025 alongside Cisco advisory cisco-sa-esa-inj-2bLVGmhX's sibling advisory cisco-sa-sma-attack-N9bf4 (covering the related CVE-2025-20393 Spam Quarantine unauthenticated remote command execution flaw, CVSS 10.0). Talos found overlaps in TTPs, infrastructure, and victimology between UAT-9686 and other China-nexus groups including APT41 and UNC5174. In that campaign, once initial root command execution was obtained on an internet-exposed appliance (Spam Quarantine feature enabled and internet-accessible), the actor deployed a custom lightweight Python backdoor dubbed AquaShell, embedded directly into an existing Python-based web-server file (observed at /data/web/euq_webui/htdocs/index.py), which passively listens for unauthenticated HTTP POST requests carrying encoded commands for shell execution. For remote access and internal pivoting the actor used AquaTunnel, a Golang ELF binary derived from the open-source ReverseSSH project, to establish reverse SSH tunnels, and the open-source tool Chisel for HTTP-based TCP/UDP tunneling to reach internal network segments. To cover its tracks, the actor used AquaPurge, a log-sanitization utility built around egrep-based keyword filtering to strip incriminating entries from appliance logs. Talos and Cisco published IOCs (file hashes and C2 IPs) and Snort rule coverage (SIDs 65617, 65643, 65644, 65645) tied to this campaign. Given the shared vendor, product line, unauthenticated-remote-to-root exploitation pattern, and immediate KEV addition, defenders should treat CVE-2026-76461 exploitation as plausibly connected to the same UAT-9686 campaign infrastructure and tooling, while noting that Cisco's September 14, 2026 advisory and the CISA KEV entry for CVE-2026-76461 do not themselves name an actor. Publicly reported victimology for the UAT-9686 campaign includes government, critical-infrastructure, and telecommunications-sector organizations, with targeting reported in Southeast Asia and Taiwan.
MITRE ATT&CK techniques used in TL-2026-2508
Collection
T1005 Data from Local System; T1114 Email Collection
Lateral Movement
T1021.004 SSH; T1210 Exploitation of Remote Services
Defense Evasion
T1027 Obfuscated Files or Information; T1070.002 Indicator Removal; T1562.001 Impair Defenses
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter; T1059.006 Python
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
Initial Access
T1190 Exploit Public-Facing Application
Persistence
Credential Access
Resource Development
T1587.004 Develop Capabilities; T1588.006 Obtain Capabilities
defense-impairment
Affected products and versions in CISA Adds Actively Exploited Cisco Secure Email Gateway SQL
- Cisco — Secure Email Gateway (AsyncOS Software)
Vulnerable versions: 15.5 and earlier; 16.0 (prior to 16.0.4-3021); 16.5 (prior to 16.5.0-780)
Fixed in: 15.5.5-0141; 16.0.4-3021; 16.5.0-780
Remediation for CISA Adds Actively Exploited Cisco Secure Email Gateway SQL
Patches
- AsyncOS 15.5.5-0141 (for 15.5 and earlier)
- AsyncOS 16.0.4-3021 (for 16.0)
- AsyncOS 16.5.0-780 (for 16.5; Cisco-recommended migration target)
Immediate actions
- Upgrade Cisco Secure Email Gateway (AsyncOS) to a fixed release immediately: 15.5.5-0141 (for 15.5 and earlier), 16.0.4-3021 (for 16.0), or 16.5.0-780 (for 16.5, Cisco's recommended target) — no workaround exists
- Per BOD 26-04, before patching verify whether internet-exposed appliances were already compromised (forensic triage requirement)
- Restrict or remove internet exposure of the appliance's Spam Quarantine feature and management interfaces
- Search mail/system logs for the SQL injection artifact pattern (e.g. `COPY ... TO PROGRAM`) and for unexpected modifications to /data/web/euq_webui/htdocs/index.py
- Hunt for outbound connections to the known UAT-9686 C2 IPs: 172.233.67.176, 172.237.29.147, 38.54.56.95
Workarounds
- None — Cisco states no workaround exists; upgrading to a fixed release is required
Longer-term hardening
- Deploy file-integrity monitoring on appliance web-server directories to catch webshell implantation such as AquaShell
- Segment internet-facing email security appliances from internal networks to limit reverse-tunnel pivoting (AquaTunnel/Chisel)
- Enable and centrally ship appliance logs off-box so on-device log tampering (AquaPurge) cannot erase evidence
- Apply Cisco Snort rule coverage (SIDs 65617, 65643, 65644, 65645) associated with the related UAT-9686 campaign
CVEs associated with CISA Adds Actively Exploited Cisco Secure Email Gateway SQL
Weaknesses (CWE) in CISA Adds Actively Exploited Cisco Secure Email Gateway SQL
CWE-89
Timeline of CISA Adds Actively Exploited Cisco Secure Email Gateway SQL
- UAT-9686 intrusion activity against internet-exposed Cisco Secure Email Gateway / Secure Email and Web Manager appliances is underway (Cisco Talos reports exploitation since at least late November 2025; exact start date approximate).
- Cisco Talos publicly discloses the UAT-9686 campaign (blog.talosintelligence.com/uat-9686), and Cisco publishes advisory cisco-sa-sma-attack-N9bf4 covering the related CVE-2025-20393 Spam Quarantine unauthenticated RCE (CVSS 10.0), detailing the AquaShell, AquaTunnel, AquaPurge, and Chisel tooling used against the same appliance family.
- Public timeline reconstructions (The Hacker News) place the earliest detected in-the-wild exploitation of CVE-2026-76461 around August 2026, well ahead of Cisco's 2026-09-14 public disclosure (exact date not published).
- Cisco TAC identified the SQL injection vulnerability (Cisco Bug ID CSCwu56234) while resolving a customer support case; Cisco PSIRT subsequently confirmed active in-the-wild exploitation in September 2026.
- Cisco releases a September 2026 AsyncOS security-hardening update for Secure Email Gateway.
- Cisco simultaneously patched four related AsyncOS vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443) in the same release, with no evidence of active exploitation for any of the four.
- Cisco PSIRT confirmed active in-the-wild exploitation of CVE-2026-76461 prior to patch availability (true zero-day) and stated multiple customers were identified with indicators of compromise, though exact scope was not disclosed.
- TL-Intel Harness ingests the CISA KEV addition for CVE-2026-76461 via the CISA Cybersecurity Advisories RSS feed.
- The Canadian Centre for Cyber Security publishes advisory AV26-921 covering CVE-2026-76461.
- CISA adds CVE-2026-76461 to the Known Exploited Vulnerabilities Catalog citing confirmed active exploitation, setting a BOD 26-04 remediation due date of September 17, 2026 for FCEB agencies.
- Cisco publishes advisory cisco-sa-esa-inj-2bLVGmhX disclosing CVE-2026-76461, an unauthenticated SQL injection in AsyncOS email parsing that leads to root-level command execution, and confirms evidence of active exploitation.
- Shadowserver reported tracking more than 400 internet-exposed Cisco Secure Email Gateway appliances at the time of public disclosure.
- SOC Prime reported that Cisco directly contacted affected cloud-hosted Secure Email Gateway customers regarding CVE-2026-76461.
- BOD 26-04 remediation deadline for U.S. Federal Civilian Executive Branch agencies to patch or mitigate CVE-2026-76461.
Update history for TL-2026-2508
- 2026-09-15 — CVE-2026-76461: Cisco Secure Email Gateway Zero-Day Root RCE Exploited in the Wild: What changed No change to severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), or CVSS (9.8) — the existing record was already at maximum on these fields. The newer report adds depth: true pre-patch zero-day exploitation confirmed
- 2026-09-15 — CVE-2026-76461: Critical Cisco Secure Email Gateway SQL Injection Enables Unauthenticated Root RCE: What changed No field escalation: severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and CVSS (9.8) already match across both reports. The newer report adds the specific SQL-to-OS-command mechanism (PostgreSQL COPY ... TO PROGRA
Sources cited for CISA Adds Actively Exploited Cisco Secure Email Gateway SQL
- CISA Adds One Known Exploited Vulnerability to Catalog
- CISA Known Exploited Vulnerabilities Catalog
- Cisco Security Advisory: Cisco Secure Email Gateway SQL Injection Vulnerability (cisco-sa-esa-inj-2bLVGmhX)
- Cisco Security Advisory: Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager (cisco-sa-sma-attack-N9bf4)
- UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
- NVD - CVE-2026-76461
- BOD 26-04: Prioritizing Security Updates Based on Risk
- BOD 26-04 Implementation Guidance: Forensic Triage Requirements
- CVE-2026-76461: Cisco Secure Email SQL Injection (CVSS 9.8)
- Actively Exploited SQL Injection in Cisco Secure Email Gateway
More in vulnerability
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Link
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wild
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)
Detection coverage for TL-2026-2508
As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2508 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.