Threat Brief — 2026-09-16 — Single Email to Root on Cisco Gateway
New technical details have emerged on the Cisco Secure Email Gateway SQL injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalogue two days ago. The flaw is now described as enabling root-level access from a single inbound email, with no viable bypass — raising the stakes for any unpatched gateway exposed to mail flow. No other fresh findings were ingested in this window.
Top items
- Cisco Secure Email Gateway SQL injection — single-email root access confirmed. The SQL injection vulnerability in Cisco Secure Email Gateway (version 9.8) is actively exploited in the wild and was added to CISA's KEV catalogue on 2026-09-14. A new analysis characterises the attack as requiring only a single crafted email to achieve root-level access with no bypass possible, making this one of the most severe mail-gateway compromises currently observed. Organisations running affected versions should treat this as an immediate-priority remediation. This is a developing story; it was first reported 2026-09-14 by CISA (src: CISA Current Activity); the new root-access detail comes from (src: Anquanke).
Themes
Email as a direct root-level attack vector. The Cisco gateway exploit underscores that inbound mail no longer merely delivers secondary payloads — in this case, a single message is the entire chain to root on a critical infrastructure appliance. Gateways that inspect and process mail at the OS level represent a high-value, low-interaction target where one message can compromise the whole mail infrastructure.
