Cisco 郵件閘道 SQL 注入遭實際利用,未驗證攻擊者可取得 root 權限執行指令Cisco email gateway SQL injection exploited in the wild, giving unauthenticated attackers root command execution
受影響Affected Cisco Secure Email Gateway 的 AsyncOS 軟體;請依原廠公告確認受影響版本AsyncOS Software for Cisco Secure Email Gateway — check the vendor advisory for affected releases
發生什麼事What happened
Cisco 警告 Secure Email Gateway 的 AsyncOS 軟體存在重大漏洞並已遭實際利用。編號 CVE-2026-76461,CVSS 9.8,成因是郵件解析邏輯的驗證不足,未經驗證的遠端攻擊者可藉此在底層作業系統上以 root 權限執行任意指令。CISA 於 9 月 14 日將其列入 KEV。
Cisco warned that a critical flaw in AsyncOS Software for Cisco Secure Email Gateway is under active exploitation. Tracked as CVE-2026-76461 with a CVSS score of 9.8, it stems from insufficient validation in the email parsing logic, allowing an unauthenticated remote attacker to execute arbitrary commands with root privileges on the underlying operating system. CISA added it to KEV on 14 September.
攻擊手法Attack technique
漏洞位於郵件解析環節,這一點決定了它的嚴重性。郵件閘道的職責就是收下並剖析每一封進來的信——攻擊者不需要誘使任何人點擊、不需要有效憑證,只要把構造過的郵件寄到你的網域,設備在處理它的過程中就被攻陷。
這是一條零點擊的路徑。而且郵件閘道位於網路邊界、通常對全網際網路開放、又持有解密後的郵件內容與寄送憑證。拿下它等同同時取得郵件內容的存取權與一個內網立足點。
The flaw sits in email parsing, and that placement determines its severity. A mail gateway's entire job is to accept and parse every message that arrives — so an attacker needs no click, no valid credentials, only to send a crafted message to your domain. The appliance is compromised in the course of doing its job.
This is a zero-click path. And a mail gateway sits at the network edge, is typically reachable from the whole internet, and holds decrypted message content plus sending credentials. Owning it grants both access to mail and a foothold inside.
影響範圍Who is affected
使用 Cisco Secure Email Gateway 的組織。因為攻擊來自「收信」這個無法關閉的功能,沒有「暫時停用該功能」這個緩解選項,只能修補或下線。
Any organisation running Cisco Secure Email Gateway. Because the attack arrives through receiving mail — a function you cannot switch off — there is no "temporarily disable the feature" mitigation. Patch or take it offline.
該怎麼做What to do
1. 立即套用 Cisco 的修補程式。這是本期優先序最高的項目。
2. 假設已遭入侵並盤查:檢視設備上的異常程序、非預期的設定變更、新增的帳號、對外連線紀錄。
3. 輪換該設備持有的所有憑證,包含與郵件服務、目錄服務、日誌平台之間的認證資訊。
4. 檢視郵件流紀錄,確認有無非預期的轉寄規則或郵件被外送到不明位址。
5. 若設備管理介面對外開放,一併收回到管理網段。
1. Apply Cisco's patch immediately. This is the highest-priority item in this issue.
2. Assume compromise and hunt: anomalous processes on the appliance, unexpected configuration changes, new accounts, outbound connections.
3. Rotate every credential the appliance holds, including authentication to mail services, directory services, and logging platforms.
4. Review mail flow logs for unexpected forwarding rules or messages sent to unfamiliar destinations.
5. If the management interface is internet-facing, pull it back to a management segment.
偵測建議Detection
郵件閘道遭入侵後,最可靠的訊號在設備的對外連線而非郵件內容——正常運作的閘道對外連線目的地相當固定(郵件伺服器、更新來源、信譽查詢服務)。出現其他目的地就值得追查。設備本機日誌在被取得 root 之後不可盡信,請以網路側紀錄比對。
After a gateway compromise, the most reliable signal is the appliance's own outbound connections rather than message content — a healthy gateway talks to a fairly fixed set of destinations (mail servers, update sources, reputation services). Anything else warrants investigation. Do not rely solely on on-box logs once root has been obtained; corroborate from the network side.
MITRE ATT&CK
本則涉及的術語Jargon in this advisory
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution · The Hacker News
- 美國當局將思科郵件閘道SQL注入漏洞列KEV · iThome
- CVE-2026-76461 — NVD · NVD