Skip to content
arrow-alt-circle-up icon

Cyber Incident?

arrow-alt-circle-up icon

Call 00800 1744 0000

arrow-alt-circle-up icon

See all Threat Responses

Dutch follows English

A critical vulnerability in Cisco Secure Email Gateway is being actively exploited by attackers. Attackers can take complete control of affected systems without needing any passwords or credentials. Cisco has released security updates that should be applied immediately to protect your email infrastructure from complete system compromise [1].
 
Description
A vulnerability has been discovered in Cisco Secure Email Gateway (AsyncOS Software) tracked as CVE-2026-76461. The vulnerability exists in how the email gateway processes incoming email messages. Improper input validation in the email parser allows a malicious email to inject unauthorised SQL commands, without needing any authentication or credentials.
 
Impact
We estimate the impact of this vulnerability as high.
The vulnerability has a CVSS (v3) score of 9.8. If successfully exploited, attackers can execute arbitrary SQL commands on the email gateway. This can lead to complete system compromise, including the ability to run any command with root-level access on the underlying operating system. Attackers could potentially compromise sensitive information and system configurations, use the gateway as a stepping stone for further attacks, or disable email security protections.
 
Risk
We estimate the risk of this vulnerability as high.
Cisco has confirmed that this vulnerability is being actively exploited in the wild [2]. An unauthenticated attacker can exploit the vulnerability by sending a specially crafted email containing malicious SQL that the Cisco Secure Email Gateway fails to validate correctly. No authentication is required. Given the active exploitation, ease of exploitation, and severity of potential impact, immediate action is required.
 
Mitigation
Cisco has released security updates that fix this vulnerability [2]. Apply the updates provided in Cisco's security advisory as soon as possible. Until updates can be applied, consider implementing additional monitoring and access controls around Cisco Secure Email Gateway systems.
It is recommended to upgrade to version AsyncOS 16.5.0-780. If upgrading to 16.5 is not immediately possible, install at least the fixed release for your current version branch:
  • 15.5 or earlier: upgrade to 15.5.5-014 or later.
  • 16.0: upgrade to 16.0.4-302 or later.
  • 16.5: upgrade to 16.5.0-780 or later.
The Cisco Secure Email Gateway SQL Injection Vulnerability is included in Cisco's September 2026 security hardening release for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, addressing a broader set of vulnerabilities identified during internal security reviews [3].
No workarounds have been published for these vulnerabilities.
 
What should you do?
  • Immediately identify all Cisco Secure Email Gateway systems in your environment and apply the security updates provided by Cisco.
  • Check your vulnerable systems for signs of compromise using the indicators of compromise (IoCs) provided in Cisco's advisory [2].
    • Review the mail_logs and look for malicious SQL statements. For example using: ‘cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]’
    • Cross-check network and firewall logging outside of the affected device(s). It is likely that attackers will cover their tracks by removing any evidence on the device.
If you need assistance identifying affected systems or applying updates, contact your IT team or Northwave immediately.
 
What will Northwave do?
We will continue to monitor your environment for any suspicious activity related to this vulnerability. We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can call us by phone or send us an email if you would like additional information.
 

E-mail: soc@northwave-cybersecurity.com

Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000



Disclaimer applies, see below.

Sources

[1]: https://advisories.ncsc.nl/2026/ncsc-2026-0368.html

[2]:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

[3]:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm


 

Een kritieke kwetsbaarheid in Cisco Secure Email Gateway wordt momenteel actief misbruikt door aanvallers. Aanvallers kunnen de volledige controle over getroffen systemen verkrijgen zonder dat zij wachtwoorden of andere inloggegevens nodig hebben. Cisco heeft beveiligingsupdates uitgebracht die onmiddellijk moeten worden geïnstalleerd om uw e-mailinfrastructuur tegen een volledige systeemcompromittering te beschermen [1].
 
Beschrijving
Er is een kwetsbaarheid ontdekt in Cisco Secure Email Gateway (AsyncOS Software), geregistreerd als CVE-2026-76461. De kwetsbaarheid bevindt zich in de manier waarop de e-mailgateway inkomende e-mailberichten verwerkt. Door onvoldoende invoervalidatie in de e-mailparser kan een kwaadaardig e-mailbericht ongeautoriseerde SQL-opdrachten injecteren, zonder dat hiervoor authenticatie of inloggegevens nodig zijn.
 
Impact
Wij schatten de impact van deze kwetsbaarheid in als hoog.
De kwetsbaarheid heeft een CVSS-score (v3) van 9,8. Bij succesvolle uitbuiting kunnen aanvallers willekeurige SQL-opdrachten uitvoeren op de e-mailgateway. Dit kan leiden tot een volledige compromittering van het systeem, waaronder de mogelijkheid om met rootrechten willekeurige opdrachten uit te voeren op het onderliggende besturingssysteem. Aanvallers kunnen mogelijk gevoelige informatie en systeemconfiguraties compromitteren, de gateway als springplank voor verdere aanvallen gebruiken of de beveiliging van het e-mailverkeer uitschakelen.
 
Risico
Wij schatten het risico van deze kwetsbaarheid in als hoog.
Cisco heeft bevestigd dat deze kwetsbaarheid actief wordt misbruikt [2]. Een niet-geverifieerde aanvaller kan de kwetsbaarheid misbruiken door een speciaal vervaardigd e-mailbericht met kwaadaardige SQL-code te verzenden, die door Cisco Secure Email Gateway niet correct wordt gevalideerd. Hiervoor is geen authenticatie vereist. Gezien het actieve misbruik, de eenvoudige wijze waarop de kwetsbaarheid kan worden uitgebuit en de ernst van de mogelijke gevolgen, is onmiddellijke actie vereist.
 
Mitigerende maatregelen
Cisco heeft beveiligingsupdates uitgebracht waarmee deze kwetsbaarheid wordt verholpen [2]. Installeer de updates uit het beveiligingsadvies van Cisco zo snel mogelijk. Overweeg aanvullende monitoring en toegangscontroles rondom Cisco Secure Email Gateway-systemen te implementeren totdat de updates kunnen worden geïnstalleerd.
Het wordt aanbevolen om te upgraden naar AsyncOS-versie 16.5.0-780. Als een upgrade naar versie 16.5 niet direct mogelijk is, installeer dan ten minste de herstelde versie voor de versiebranch die u momenteel gebruikt:
  • 15.5 of eerder: upgrade naar 15.5.5-014 of hoger.
  • 16.0: upgrade naar 16.0.4-302 of hoger.
  • 16.5: upgrade naar 16.5.0-780 of hoger.
De SQL-injectiekwetsbaarheid in Cisco Secure Email Gateway maakt deel uit van Cisco’s beveiligingsrelease van september 2026 voor Cisco Secure Email Gateway en Cisco Secure Email and Web Manager. Deze release is gericht op het verder versterken van de beveiliging en verhelpt een bredere reeks kwetsbaarheden die tijdens interne beveiligingsonderzoeken zijn vastgesteld [3].
Voor deze kwetsbaarheden zijn geen tijdelijke oplossingen gepubliceerd.
 
Wat moet u doen?
  • Breng onmiddellijk alle Cisco Secure Email Gateway-systemen binnen uw omgeving in kaart en installeer de door Cisco beschikbaar gestelde beveiligingsupdates.
  • Controleer kwetsbare systemen op tekenen van compromittering aan de hand van de indicators of compromise (IoC’s) uit het beveiligingsadvies van Cisco [2].
    • Controleer de mail_logs op kwaadaardige SQL-instructies. Gebruik hiervoor bijvoorbeeld: ‘cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]’
    • Controleer daarnaast de netwerk- en firewall logging buiten het getroffen apparaat. Het is aannemelijk dat aanvallers hun sporen proberen te wissen door bewijsmateriaal op het apparaat te verwijderen.
Als u ondersteuning nodig hebt bij het identificeren van getroffen systemen of het installeren van de updates, neem dan onmiddellijk contact op met uw IT-team of Northwave.
 
Wat doet Northwave?
Wij blijven uw omgeving monitoren op verdachte activiteiten die verband houden met deze kwetsbaarheid. Northwave houdt de ontwikkelingen omtrent deze kwetsbaarheid in de gaten. Als er belangrijke nieuwe informatie omtrent deze dreiging bekend wordt, stellen wij u hiervan op de hoogte. Als u behoefte heeft aan extra informatie zijn we zowel telefonisch als via email bereikbaar.
 

E-mail: soc@northwave-cybersecurity.com
Heeft u nu een incident? Bel ons Incident Response Team: 00800 1744 0000


Disclaimer is van toepassing, zie onder.

Bronnen

[1]: https://advisories.ncsc.nl/2026/ncsc-2026-0368.html

[2]: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

[3]:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm

 

Disclaimer

Northwave has made every effort to make this information accurate and reliable. However, the information provided is without warranty of any kind and its use is at the sole risk of the user. Northwave does not accept any responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided. We will not be liable for any loss or damage of whatever nature, direct or indirect, consequential or other, whether arising in contract, tort or otherwise, which may arise as a result of your use of, or inability to use, this information or any additional information provided by us in direct or indirect relation to the information provided here.
.