The Trusted Gateway That Became the Entry Point
Cisco Secure Email Gateway — the appliance enterprises trust to filter threats before they reach inboxes — has been actively exploited since before Monday's disclosure.
CVE-2026-76461. SQL injection. CVSS score not yet published, but Cisco confirmed active exploitation as of Monday, September 15, 2026. The vulnerability sits in AsyncOS Software versions 16.5, 16.0, and 15.5 and earlier, affecting both physical and virtual on-premises appliances.
SQL injection. In 2026. In enterprise email security infrastructure.
That's the headline, and it's damning on its own. SQL injection is first-semester secure-coding curriculum. It's the vulnerability OWASP has warned about for two decades. It's what you prevent by parameterizing database queries instead of concatenating user input into SQL strings. It's foundational, it's well-understood, and Cisco shipped it in an appliance whose entire purpose is to stop threats from reaching users.
The exploit leverages user-supplied input that the appliance fails to sanitize before passing it to a database query. An attacker injects SQL commands, the database executes them, and depending on database permissions and configuration, that yields data exfiltration, authentication bypass, command execution, lateral movement to backend systems.
Cisco Secure Email Gateway sits at the perimeter. It's an on-premises appliance or virtual machine that inspects every inbound and outbound email for malware, phishing, data loss prevention policy violations, spam. Enterprises route all mail through it. That position — between the internet and the mail server — makes it a high-value target. Compromise the email gateway and you intercept every message, exfiltrate attachments, modify content in transit, harvest credentials from phishing simulations, pivot to the mail server and from there to Active Directory.
"Actively exploited since before disclosure" means victims were compromised while Cisco was still coordinating the advisory. The timeline for when exploitation began is unknown, but disclosure on September 15 with confirmed in-wild use means attackers had access to vulnerable appliances before enterprises were warned. Zero-day or near-zero-day window.
Cisco released patches and published the advisory Monday. Affected customers running AsyncOS 16.5, 16.0, or 15.5 and earlier must upgrade to patched builds. On-premises appliances require manual deployment — download the update, schedule the maintenance window, apply it, test, monitor. That process takes days to weeks depending on change management practices, testing requirements, and whether the organization treats email infrastructure as critical enough for emergency patching.
The appliances affected are physical and virtual. Physical appliances sit in the data center, racked and networked. Virtual appliances run on VMware or Hyper-V. Both require patching, but virtual instances can be snapshot-and-rollback if something breaks, which makes testing faster and reduces risk. Physical appliances require firmware updates with longer rollback procedures.
SQL injection in email security infrastructure is a failure at multiple layers. Secure development practices should catch it in code review. Static analysis tools flag SQL concatenation patterns. Penetration testing should identify injection points. Security-focused QA should fuzz inputs. Cisco's SDL — Security Development Lifecycle — exists specifically to prevent shipping this class of vulnerability in production code, especially in products sold as security appliances.
That it shipped anyway means one of two things: the processes failed, or they were bypassed. Either the code wasn't reviewed with security in mind, or the review missed it. Either the static analysis tools weren't run, or their findings were ignored. Either penetration testing wasn't performed, or it didn't cover this code path. Or all of those happened and the vulnerability was deemed acceptable risk, deprioritized, or left for a future release.
None of those options are good when the product is an email security gateway and the vulnerability is SQL injection.
The exploitation before disclosure suggests attackers either discovered the flaw independently through vulnerability research, or obtained knowledge of it through other means — leaked Cisco internal communications, insider disclosure, or reverse-engineering a patch from another Cisco product that fixed similar logic. SQL injection vulnerabilities cluster. If one code path has it, others likely do too, especially if the codebase uses string concatenation for database queries as a pattern.
Cisco's advisory will include indicators of compromise — log signatures, file hashes, network traffic patterns — that organizations can use to hunt for evidence of exploitation in their own environments. But SQL injection attacks can be stealthy. An attacker querying the database and exfiltrating email metadata or user lists may leave minimal forensic evidence if logging isn't configured to capture full SQL queries and their results.
The risk to organizations running vulnerable Cisco Secure Email Gateway appliances: every email that passed through the appliance while it was compromised is potentially exposed. Sender, recipient, subject, attachments, message body. Business communications, contracts, financial data, HR records, legal documents, customer information. Email is where sensitive information lives in plaintext, and the email gateway sees all of it.
Patch immediately. If patching requires a multi-day testing cycle, consider whether the testing delay is worth the exposure. SQL injection in an internet-facing email security appliance with confirmed active exploitation is an emergency. The thing protecting your email became the way in.
SQL injection. 2026. Cisco Secure Email Gateway.
The irony would be funny if the consequences weren't real.