Click Icon to Copy Verbose Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:X/RL:X/RC:X
-
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
-
Vulnerable Products
This vulnerability affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration.
For information about which Cisco software releases are vulnerable, see the Fixed Software section of this advisory.
Products Confirmed Not Vulnerable
Only products listed in the Vulnerable Products section of this advisory are known to be affected by this vulnerability.
Cisco has confirmed that this vulnerability does not affect the following Cisco products:
- Secure Email and Web Manager
- Secure Web Appliance
-
To confirm any attempted exploitation of this vulnerability, review the mail_logs and look for suspicious SQL statements. If the device is part of a cluster, review the logs of each cluster device. The following is a non-exhaustive example of how a malicious SQL statement could be detected in the logs:
cisco-esa> grep -i "COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]The presence of any entry in the output may indicate malicious activity.
On Cisco Secure Email Cloud, administrators without CLI access may not be able to independently check the described indicators of compromise. Cisco has directly contacted customers who own Cisco Secure Email Cloud devices on which malicious activity was detected.
Note: Upon successful exploitation of this vulnerability, threat actors may obtain command execution with root privileges. Because of this level of access, evidence of exploitation and indicators of compromise may be removed or hidden by the threat actors. Cisco strongly recommends that administrators cross-check the network logs and the firewall logs outside of the impacted device to identify any potential suspicious activity, including but not limited to unexpected uploads that were initiated from the affected device to external IP addresses or downloads from malicious IP addresses.
-
There are no workarounds that address this vulnerability.
-
Cisco considers any workarounds and mitigations (if applicable) to be temporary solutions until an upgrade to a fixed software release is available. To remediate this vulnerability and avoid future exposure as described in this advisory, Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory.
Fixed Releases
In the following table, the left column lists Cisco software releases. The right column indicates whether a release is affected by the vulnerabilities that are described in this advisory and the first release that includes the fix for these vulnerabilities. Customers are advised to upgrade to an appropriate fixed software release as indicated in this section.
Cisco AsyncOS for Cisco Secure Email Gateway Software Release First Fixed Release 15.5 and earlier 15.5.5-0141 16.0 16.0.4-3021 16.5 16.5.0-780 1. Cisco strongly recommends that customers migrate to Release 16.5.0-780.The software can be upgraded over the network by using the System Upgrade options in the web-based management interface of the appliance.
To upgrade a device by using the web-based management interface, do the following:
- Choose System Administration > System Upgrade.
- Click Upgrade Options.
- Click Download and Install.
- Choose a release to upgrade to.
- In the Upgrade Preparation area, choose the appropriate options.
- Click Proceed to begin the upgrade. A progress bar displays the status of the upgrade.
After the upgrade is complete, the device reboots.
To upgrade a device by using the CLI, do the following:
- Run upgrade.
- Enter DOWNLOADINSTALL.
- Choose a release to upgrade to.
- Choose the appropriate options throughout the upgrade process.
After the upgrade is complete, the device reboots.
Cisco Secure Email Cloud includes Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices as part of the service solution. Cisco provides regular maintenance of the products included in this solution. Customers can also request a software upgrade by contacting Cisco Secure Email Cloud support.
Cisco has already upgraded all Cisco Secure Email Cloud devices to Release 16.5.0-780.
The Cisco Product Security Incident Response Team (PSIRT) validates only the affected and fixed release information that is documented in this advisory.
-
On-Premises Physical Devices
If exploitation is suspected on a physical appliance, Cisco recommends contacting the Cisco Technical Assistance Center (TAC) for further support. To expedite our investigation into the potential compromise, please ensure that remote access is enabled on the affected appliances. For more guidance, see FAQ for Remote Access on Cisco ESA/WSA/SMA.
On-Premises Virtual Devices
If exploitation is suspected on a virtual appliance, Cisco strongly recommends the following actions to restore a device to a secure configuration, when possible:
- Maintain forensics information, as described in the incident handling policies of the customer. Important: Record forensics information before continuing to any of the following steps. Deploying a new instance will destroy the configurations and logs.
- Deploy a new virtual machine running one of the fixed software releases.
- Rebuild the product configuration.
- Renew credentials and any cryptographic materials that are installed on the appliance.
- Continue to monitor the system for anomalous behavior.
If restoring the appliance is not possible, Cisco recommends contacting the Cisco TAC for further support.
If exploitation is not suspected and the device is running an affected software release, Cisco strongly recommends upgrading to a fixed release.
Cisco Secure Email Cloud
Cisco has conducted a thorough threat intelligence investigation on devices that belong to Cisco Secure Email Cloud. Cisco has directly contacted customers who own Cisco Secure Email Cloud devices where indicators of possible compromise were identified. Cisco is engaged in remediation and recovery operations. Cisco has already deployed mitigations that are within Cisco's management.
Additionally, Cisco strongly recommends that customers who have been contacted restore a device to a secure configuration by renewing credentials and any cryptographic materials that are installed on the appliance, when possible.
In addition, Cisco strongly recommends restricting access to the appliance and implementing robust access control mechanisms.
General Recommendations For Hardening
- Upgrade the appliance to the latest version of Cisco AsyncOS Software.
- Prevent access from the internet to the appliance. If internet access to the appliance is required, restrict appliance access to only known, trusted hosts on ports and protocols that are included in the user guides.
- For Cisco Secure Email Gateway, separate mail and management functionality onto individual network interfaces. This reduces the chance of unauthorized users accessing the internal management network. For more information, see the device user guides.
- Protect Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances behind a filtering device such as a firewall, and filter management traffic to and from the appliances while allowing only known, trusted hosts to send traffic to the appliances. Using a two-layer firewall can provide flexibility in network planning so that end users do not connect directly to the outer DMZ. See the Deployment sections of the User Guides for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.
- Regularly monitor log traffic for any unexpected traffic to or from appliances. Logging should be sent to an external server, if possible, and kept for a long enough duration so that post-event investigations can be performed with sufficient log data.
- Disable HTTP for the main administrator portal.
- Disable any network services that are not required, including HTTP and FTP. For more information about specific service functionality, see the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager user guides.
- Use a strong form of end-user authentication to the appliances, such as SAML or Lightweight Directory Access Protocol (LDAP). For more secure methods of authentication, see Authentication Options for End Users Accessing Spam Management Features.
- Change the default administrator password to a more secure variant. Restrict access to the administrator account by creating user accounts based on necessary access requirements. In addition, create operator accounts for all administrators.
- Using SSL/TLS, obtain an SSL certificate from a certificate authority (CA) or create a self-signed certificate.
Useful Resources
The following resources can help restore an affected appliance to a secure state. Some of the documents are related to a specific product, but the procedures are mostly interchangeable. If customers have specific questions about a procedure, contact Cisco TAC.
To download replacement virtual appliances, see the relevant Cisco Software Download page:
The User Guide for AsyncOS 16.5 for Cisco Secure Email and Web Manager provides more information. See the following sections:
- For information about exporting reporting data from an appliance, see Working with Reports.
- For information about how to purge messages in the quarantine, see Spam Quarantine.
- For additional information, see Centralizing Policy, Virus, and Outbreak Quarantines.
-
In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.
-
This vulnerability was found during the resolution of a Cisco TAC support case.
-
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco.
For additional information on Cisco's vulnerability management, disclosure cadence, and software patching strategy, see Cisco's Transition to a Risk-Based Vulnerability Disclosure Model.
-
Show LessVersion Description Section Status Date 1.0 Initial public release. — Final 2026-SEP-14
-
SOFTWARE DOWNLOADS AND TECHNICAL SUPPORT
The Cisco Support and Downloads page on Cisco.com provides information about licensing and downloads. This page can also display customer device support coverage for customers who use the My Devices tool. Please note that customers may download only software that was procured from Cisco directly or through a Cisco authorized reseller or partner and for which the license is still valid.
Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco Technical Assistance Center (TAC). Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade.
When considering software upgrades, customers are advised to regularly consult the advisories for the relevant Cisco products to determine exposure and a complete upgrade solution. In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers.
LEGAL DISCLAIMER DETAILS
CISCO DOES NOT MAKE ANY EXPRESS OR IMPLIED GUARANTEES OR WARRANTIES OF ANY KIND, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. WITHOUT LIMITING THE GENERALITY OF THE FOREGOING, CISCO DOES NOT GUARANTEE THE ACCURACY OR COMPLETENESS OF THIS INFORMATION. THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
Copies or summaries of the information contained in this Security Advisory may lack important information or contain factual errors. Customers are advised to visit the Cisco Security Advisories page for the most recent version of this Security Advisory. The Cisco Product Security Incident Response Team (PSIRT) assesses only the affected and fixed release information that is documented in this advisory. See the Cisco Security Vulnerability Policy for more information.