AllCyberNews

CVE-2026-76461

Cisco Secure Email Gateway SQL Injection Vulnerability

CVSS 9.8 critical · Cisco Cisco Secure Email · published 2026-09-14

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Coverage 2 sources

  1. 2026-09-14 CISA Cybersecurity Advisories high CISA Adds One Known Exploited Vulnerability to Catalog

    CISA added CVE-2026-76461, a Cisco Secure Email Gateway SQL injection vulnerability, to its Known Exploited Vulnerabilities Catalog.

  2. 2026-09-15 Help Net Security critical Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

    Cisco patches zero-day SQL injection vulnerability (CVE-2026-76461) in Secure Email Gateway.

Also covered