---
analysis: A simple detection rule on 'COPY TO PROGRAM' in process command lines is
  easily evaded by shell obfuscation; this hunt combines version-based scoping, fleet
  prevalence, and parent-child process relationships to identify exploitation results.
blind_spots:
- id: appliance-visibility-gap
  question: Does the appliance internal mail log contain the SQL statement?
  requires: appliance native logs (mail_logs)
  risk: The hunt detects the process outcome, but the most definitive proof resides
    in logs not always ingested as hb_ events.
  stage: arbitrary-command-execution
coverage:
- stage: vulnerability-identification
  status: covered
  steps:
  - identify-vulnerable-appliances
- reason: Exploit delivery occurs inside the SMTP protocol stream, which is not visible
    on standard process or network surfaces.
  stage: exploit-delivery-crafted-email
  status: not_visible
- stage: arbitrary-command-execution
  status: covered
  steps:
  - rare-process-baseline
  - detect-sqli-command-artifacts
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: CVE-2026-76461 is actively exploited in the wild as a zero-day and
    allows unauthenticated root command execution on critical email infrastructure.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An unauthenticated attacker has exploited CVE-2026-76461 by sending a
  crafted email to a Cisco Secure Email Gateway, resulting in root-level command execution
  from a database process.
labels:
- hunt
- attack.t1190
- attack.t1566
- attack.t1059
- execution
- initial access
name: Cisco Secure Email Gateway SQLi Exploitation
parameters:
  lookback_days:
    default: '14'
    description: Number of days of history to examine.
    from:
      kind: manual
      observed: '2026-09-15'
      ref: default
    type: number
  scope_hosts:
    default: []
    description: Hostnames identified as vulnerable in the first step; leave empty
      to hunt all hosts.
    from:
      kind: manual
      observed: '2026-09-15'
      ref: default
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Scope to the Cisco Secure Email Gateway footprint using the software inventory
  and vulnerability findings; prioritize assets with active CVE findings.
references:
- name: "Rapid7 \u2014 CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability\
    \ Exploited in the Wild"
  url: https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild
related:
- hunt: email-gateway-persistence
  reason: Exploitation may lead to the installation of persistence mechanisms inside
    the appliance software.
  relation: follows
scenario:
  stages:
  - name: Identification of Vulnerable Appliances
    observables:
    - CVE-2026-76461
    - Cisco AsyncOS 15.5
    - Cisco AsyncOS 16.0
    - Cisco AsyncOS 16.5
    slug: vulnerability-identification
    tactic: initial-access
    techniques:
    - T1190
  - name: Unauthenticated Exploit via Crafted Email
    observables:
    - specially crafted email
    - SMTP traffic on port 25
    slug: exploit-delivery-crafted-email
    tactic: initial-access
    techniques:
    - T1190
    - T1566
  - name: Root-Level Command Execution
    observables:
    - COPY.*TO PROGRAM
    - root-level arbitrary commands
    - grep -i "COPY.*TO PROGRAM" mail_logs
    slug: arbitrary-command-execution
    tactic: execution
    techniques:
    - T1059
  summary: CVE-2026-76461 is a critical SQL injection vulnerability in Cisco Secure
    Email Gateway that allows unauthenticated, remote attackers to execute arbitrary
    commands with root privileges. Exploitation is achieved by sending a specially
    crafted email through the gateway, which triggers a malicious SQL statement such
    as 'COPY TO PROGRAM' during email processing. This vulnerability was exploited
    as a zero-day in September 2026 before patches were available.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Cisco Secure Email Gateway SQLi Exploitation

This hunt identifies Cisco Secure Email Gateway appliances running vulnerable AsyncOS versions and monitors for behavioral indicators of SQL injection exploitation. The attack uses a PostgreSQL-specific command (COPY TO PROGRAM) to achieve root-level execution. Because this occurs inside the appliance's mail processing pipeline, the hunt focuses on identifying rare process execution patterns and parent-child anomalies on vulnerable hosts.

## identify-vulnerable-appliances
<!-- Identify Vulnerable Cisco Appliances -->
CVE-2026-76461 is actively exploited in the wild as a zero-day and allows unauthenticated root command execution on affected appliances; the hunt identifies vulnerable assets through software and vulnerability inventory.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hostnames and versions. Rows from hb_vulnerability_finding prioritize
  assets already identified by scanners.
reads:
- device_hostname
- package_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, package_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%asyncos%' OR LOWER(package_name) LIKE '%ironport%') AND (package_version LIKE '15.5%' OR package_version LIKE '16.0%' OR package_version LIKE '16.5%') UNION SELECT resource_uid AS device_hostname, affected_package_name AS package_name, affected_package_version AS package_version FROM hb_vulnerability_finding WHERE cve_uid = 'CVE-2026-76461'
```

## rare-process-baseline
<!-- Rare Processes on Vulnerable Appliances -->
The hunt stacks process execution on identified Cisco hosts to find unique attacker-driven commands while excluding fleet-wide noise.

```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: Rare command lines that appear on only one or two Cisco appliances; these
  often represent the second stage of exploitation.
prevalence:
  by: device_hostname
  key:
  - process_name
  - process_cmd_line
  rare_below: 3
reads:
- process_name
- process_cmd_line
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT process_name, process_cmd_line, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY process_name, process_cmd_line HAVING host_count <= 2 ORDER BY host_count ASC
```

## detect-sqli-command-artifacts
<!-- Detect SQLi Command Execution Artifacts -->
The query searches for PostgreSQL COPY TO PROGRAM exploitation artifacts and staging in world-writable directories.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Shells spawned by database or mail processes, or command lines containing
  SQL injection artifacts.
reads:
- device_hostname
- process_name
- process_cmd_line
- parent_process_name
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-29'
~~~
SELECT device_hostname, process_name, process_cmd_line, parent_process_name, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_cmd_line) LIKE '%copy%to%program%' OR LOWER(process_cmd_line) LIKE '%/tmp/%' OR LOWER(process_cmd_line) LIKE '%/dev/shm/%' OR LOWER(parent_process_name) LIKE '%postgres%' OR LOWER(parent_process_name) LIKE '%mail%') AND (LOWER(process_name) LIKE '%sh' OR LOWER(process_name) LIKE '%bash' OR LOWER(process_name) LIKE '%nc' OR LOWER(process_name) LIKE '%python%') AND time >= datetime('now', '-{{lookback_days}} days')
```

## triage-exposure
<!-- Evaluate Exposure and Exploitation -->
```agent target=hunter
cite: required
context:
- identify-vulnerable-appliances
- rare-process-baseline
- detect-sqli-command-artifacts
max_iterations: 5
objective: Determine if any host identified in the scoping query has exhibited process
  activity consistent with CVE-2026-76461 exploitation.
success_criteria: A list of hosts with a malicious, suspicious, or benign verdict
  citing specific rows.
tools:
- endpoint
```

## route-by-verdict
<!-- Route Based on Verdict -->
if~: "the triage verdict is malicious or suspicious for at least one host" (confidence: high, judge=hunter)
then: → remediation-review
indeterminate: → remediation-review
unavailable: → remediation-review (blind_spot: appliance-visibility-gap)
else: → close-out

## remediation-review
<!-- Remediation and Incident Review -->
```manual target=analyst
1. Prioritize emergency upgrades for all hosts identified in the scoping query.
2. For hosts with suspicious activity, run grep -i 'COPY.*TO PROGRAM' mail_logs on the appliance.
3. Inspect any shell activity spawned from postgres processes for persistence.
```
→ end

## close-out
<!-- Close Out -->
```manual target=analyst
Confirm no anomalous activity was detected and track any remaining vulnerable appliances for the next maintenance window.
```
→ end
