CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog

CISA Adds Actively Exploited Cisco Secure Email Gateway SQL (TL-2026-2508) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-14 and last reviewed 2026-09-15. It is attributed to UAT-9686 (China) with medium confidence, affects Cisco Secure Email Gateway (AsyncOS Software), references 1 CVE (CVE-2026-76461), maps to 22 MITRE ATT&CK techniques (T1005, T1021.004, T1027), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2508

Threat ID
TL-2026-2508
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-14
Last reviewed
2026-09-15
Attribution
UAT-9686
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, critical infrastructure, telecoms
Target regions
Southeast Asia, taiwan
Detection rules
9
Indicators of compromise
17
Updates
2026-09-15 · 2 updates · revalidated 2× · latest source

Malware and tooling in CISA Adds Actively Exploited Cisco Secure Email Gateway SQL

Malware and tooling: AquaPurge, AquaShell, AquaTunnel, Chisel, ReverseSSH

CISA added CVE-2026-76461, a critical (CVSS 9.8) SQL injection in Cisco AsyncOS for Secure Email Gateway, to its KEV Catalog on September 14, 2026 after confirming active exploitation; an unauthenticated attacker can trigger the flaw with a crafted email to gain root-level command execution on the appliance. FCEB remediation is due September 17, 2026 under BOD 26-04.

How CISA Adds Actively Exploited Cisco Secure Email Gateway SQL works

CVE-2026-76461 is a SQL injection vulnerability (CWE-89) in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway (formerly the Cisco Email Security Appliance). Insufficient validation of email content allows an unauthenticated, remote attacker to send a specially crafted email containing malicious SQL statements to an affected device; the injected SQL is used to execute arbitrary operating-system commands with root privileges on the underlying appliance, giving the attacker full control with no authentication and no user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, 9.8/CRITICAL). Cisco Secure Email and Web Manager and Cisco Secure Web Appliance are not affected by this specific CVE. Cisco published advisory cisco-sa-esa-inj-2bLVGmhX and confirmed evidence of active, in-the-wild exploitation; CISA added the CVE to its Known Exploited Vulnerabilities Catalog the same day (September 14, 2026), triggering a Binding Operational Directive 26-04 remediation deadline of September 17, 2026 for U.S. Federal Civilian Executive Branch agencies, including a requirement to verify whether internet-exposed systems were compromised prior to patching. No workaround exists; Cisco's fixed releases are AsyncOS 15.5.5-0141, 16.0.4-3021, and 16.5.0-780 (Cisco recommends migrating to 16.5.0-780). Cisco Cloud-hosted Secure Email instances were already patched by the vendor.

This disclosure follows a documented pattern of exploitation against the same appliance family. Cisco Talos assesses with MODERATE confidence that a China-nexus threat actor it tracks as UAT-9686 has been exploiting Cisco Secure Email Gateway and Secure Email and Web Manager appliances since at least late November 2025, publicly disclosed December 10, 2025 alongside Cisco advisory cisco-sa-esa-inj-2bLVGmhX's sibling advisory cisco-sa-sma-attack-N9bf4 (covering the related CVE-2025-20393 Spam Quarantine unauthenticated remote command execution flaw, CVSS 10.0). Talos found overlaps in TTPs, infrastructure, and victimology between UAT-9686 and other China-nexus groups including APT41 and UNC5174. In that campaign, once initial root command execution was obtained on an internet-exposed appliance (Spam Quarantine feature enabled and internet-accessible), the actor deployed a custom lightweight Python backdoor dubbed AquaShell, embedded directly into an existing Python-based web-server file (observed at /data/web/euq_webui/htdocs/index.py), which passively listens for unauthenticated HTTP POST requests carrying encoded commands for shell execution. For remote access and internal pivoting the actor used AquaTunnel, a Golang ELF binary derived from the open-source ReverseSSH project, to establish reverse SSH tunnels, and the open-source tool Chisel for HTTP-based TCP/UDP tunneling to reach internal network segments. To cover its tracks, the actor used AquaPurge, a log-sanitization utility built around egrep-based keyword filtering to strip incriminating entries from appliance logs. Talos and Cisco published IOCs (file hashes and C2 IPs) and Snort rule coverage (SIDs 65617, 65643, 65644, 65645) tied to this campaign. Given the shared vendor, product line, unauthenticated-remote-to-root exploitation pattern, and immediate KEV addition, defenders should treat CVE-2026-76461 exploitation as plausibly connected to the same UAT-9686 campaign infrastructure and tooling, while noting that Cisco's September 14, 2026 advisory and the CISA KEV entry for CVE-2026-76461 do not themselves name an actor. Publicly reported victimology for the UAT-9686 campaign includes government, critical-infrastructure, and telecommunications-sector organizations, with targeting reported in Southeast Asia and Taiwan.

MITRE ATT&CK techniques used in TL-2026-2508

Collection

T1005 Data from Local System; T1114 Email Collection

Lateral Movement

T1021.004 SSH; T1210 Exploitation of Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1070.002 Indicator Removal; T1562.001 Impair Defenses

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1059.004 Command and Scripting Interpreter; T1059.006 Python

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505.003 Web Shell

Credential Access

T1552 Unsecured Credentials

Resource Development

T1587.004 Develop Capabilities; T1588.006 Obtain Capabilities

defense-impairment

T1685.006 Clear Linux or Mac System Logs

Affected products and versions in CISA Adds Actively Exploited Cisco Secure Email Gateway SQL

  • Cisco — Secure Email Gateway (AsyncOS Software)
    Vulnerable versions: 15.5 and earlier; 16.0 (prior to 16.0.4-3021); 16.5 (prior to 16.5.0-780)
    Fixed in: 15.5.5-0141; 16.0.4-3021; 16.5.0-780

Remediation for CISA Adds Actively Exploited Cisco Secure Email Gateway SQL

Patches

  • AsyncOS 15.5.5-0141 (for 15.5 and earlier)
  • AsyncOS 16.0.4-3021 (for 16.0)
  • AsyncOS 16.5.0-780 (for 16.5; Cisco-recommended migration target)

Immediate actions

  • Upgrade Cisco Secure Email Gateway (AsyncOS) to a fixed release immediately: 15.5.5-0141 (for 15.5 and earlier), 16.0.4-3021 (for 16.0), or 16.5.0-780 (for 16.5, Cisco's recommended target) — no workaround exists
  • Per BOD 26-04, before patching verify whether internet-exposed appliances were already compromised (forensic triage requirement)
  • Restrict or remove internet exposure of the appliance's Spam Quarantine feature and management interfaces
  • Search mail/system logs for the SQL injection artifact pattern (e.g. `COPY ... TO PROGRAM`) and for unexpected modifications to /data/web/euq_webui/htdocs/index.py
  • Hunt for outbound connections to the known UAT-9686 C2 IPs: 172.233.67.176, 172.237.29.147, 38.54.56.95

Workarounds

  • None — Cisco states no workaround exists; upgrading to a fixed release is required

Longer-term hardening

  • Deploy file-integrity monitoring on appliance web-server directories to catch webshell implantation such as AquaShell
  • Segment internet-facing email security appliances from internal networks to limit reverse-tunnel pivoting (AquaTunnel/Chisel)
  • Enable and centrally ship appliance logs off-box so on-device log tampering (AquaPurge) cannot erase evidence
  • Apply Cisco Snort rule coverage (SIDs 65617, 65643, 65644, 65645) associated with the related UAT-9686 campaign

CVEs associated with CISA Adds Actively Exploited Cisco Secure Email Gateway SQL

CVE-2026-76461

Weaknesses (CWE) in CISA Adds Actively Exploited Cisco Secure Email Gateway SQL

CWE-89

Timeline of CISA Adds Actively Exploited Cisco Secure Email Gateway SQL

  • UAT-9686 intrusion activity against internet-exposed Cisco Secure Email Gateway / Secure Email and Web Manager appliances is underway (Cisco Talos reports exploitation since at least late November 2025; exact start date approximate).
  • Cisco Talos publicly discloses the UAT-9686 campaign (blog.talosintelligence.com/uat-9686), and Cisco publishes advisory cisco-sa-sma-attack-N9bf4 covering the related CVE-2025-20393 Spam Quarantine unauthenticated RCE (CVSS 10.0), detailing the AquaShell, AquaTunnel, AquaPurge, and Chisel tooling used against the same appliance family.
  • Public timeline reconstructions (The Hacker News) place the earliest detected in-the-wild exploitation of CVE-2026-76461 around August 2026, well ahead of Cisco's 2026-09-14 public disclosure (exact date not published).
  • Cisco TAC identified the SQL injection vulnerability (Cisco Bug ID CSCwu56234) while resolving a customer support case; Cisco PSIRT subsequently confirmed active in-the-wild exploitation in September 2026.
  • Cisco releases a September 2026 AsyncOS security-hardening update for Secure Email Gateway.
  • Cisco simultaneously patched four related AsyncOS vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443) in the same release, with no evidence of active exploitation for any of the four.
  • Cisco PSIRT confirmed active in-the-wild exploitation of CVE-2026-76461 prior to patch availability (true zero-day) and stated multiple customers were identified with indicators of compromise, though exact scope was not disclosed.
  • TL-Intel Harness ingests the CISA KEV addition for CVE-2026-76461 via the CISA Cybersecurity Advisories RSS feed.
  • The Canadian Centre for Cyber Security publishes advisory AV26-921 covering CVE-2026-76461.
  • CISA adds CVE-2026-76461 to the Known Exploited Vulnerabilities Catalog citing confirmed active exploitation, setting a BOD 26-04 remediation due date of September 17, 2026 for FCEB agencies.
  • Cisco publishes advisory cisco-sa-esa-inj-2bLVGmhX disclosing CVE-2026-76461, an unauthenticated SQL injection in AsyncOS email parsing that leads to root-level command execution, and confirms evidence of active exploitation.
  • Shadowserver reported tracking more than 400 internet-exposed Cisco Secure Email Gateway appliances at the time of public disclosure.
  • SOC Prime reported that Cisco directly contacted affected cloud-hosted Secure Email Gateway customers regarding CVE-2026-76461.
  • BOD 26-04 remediation deadline for U.S. Federal Civilian Executive Branch agencies to patch or mitigate CVE-2026-76461.

Update history for TL-2026-2508

Sources cited for CISA Adds Actively Exploited Cisco Secure Email Gateway SQL

More in vulnerability

Detection coverage for TL-2026-2508

As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2508 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats