CVE-2026-76461
Cisco Secure Email Gateway SQL Injection Vulnerability
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Coverage 2 sources
-
2026-09-14
CISA Cybersecurity Advisories
high
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2026-76461, a Cisco Secure Email Gateway SQL injection vulnerability, to its Known Exploited Vulnerabilities Catalog.
-
2026-09-15
Help Net Security
critical
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Cisco patches zero-day SQL injection vulnerability (CVE-2026-76461) in Secure Email Gateway.
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands