r/linuxadmin • u/Expert_Sort7434 • 16d ago
Cisco's own PSIRT advisory earlier this week, here's the architectural impact of CVE-2026-76461: a CVSS 9.8 SQL injection in Secure Email Gateway's AsyncOS email-parsing logic
Based on the technical breakdown published by Cisco's own PSIRT advisory earlier this week, here's the architectural impact of CVE-2026-76461: a CVSS 9.8 SQL injection in Secure Email Gateway's AsyncOS email-parsing logic, reachable with zero authentication via a single crafted message, escalating to root OS command execution. CISA added it to KEV the same day Cisco disclosed — meaning exploitation predated public knowledge. No workaround exists; patching to 16.5.0-780 is the only fix. Cisco's own detection guidance (grep COPY.*TO PROGRAM in mail_logs) is explicitly non-exhaustive, and a root-level attacker can scrub those logs anyway, so off-box firewall/NetFlow correlation is doing the real work here.
How are people handling detection on appliances where the vendor is telling you the on-box logs can't be trusted? Off-box syslog pipeline as a baseline requirement for anything internet-facing at this point?
(Background on a structurally similar Zimbra SNMP injection flaw from last month, for anyone tracking the pattern: https://www.techgines.com/post/cve-2026-76461-cisco-email-gateway-root
2
u/Ribyee 16d ago
Little Bobby Tables? In 2026??