CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability

Published Sep 14, 2026
·
Updated

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Other sources

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

— CISA

Affected Software

10 affected components
Cisco Secure Email Gateway
All of the following
Any of the following
Cisco AsyncOS<15.5.5-014
Cisco AsyncOS>=16.0<16.0.4-302
Cisco AsyncOS>=16.5<16.5.0-780
Any of the following
Cisco Secure Email Gateway Virtual Appliance C100v
Cisco Secure Email Gateway Virtual Appliance C300v
Cisco Secure Email Gateway Virtual Appliance C600v
Cisco Secure Email Gateway C195
Cisco Secure Email Gateway C395
Cisco Secure Email Gateway C695

Event History

Sep 14, 2026
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this vulnerability?

An unauthenticated remote attacker can exploit it by sending a crafted email message through an affected Cisco Secure Email Gateway device. No prior access or user interaction is described as necessary.

2

What level of access could a successful attacker obtain?

Successful exploitation can allow arbitrary SQL statements to be executed and can lead to arbitrary command execution with root privileges on the underlying operating system.

3

What should defenders look for to identify exploitation attempts?

The provided information identifies crafted email messages containing malicious SQL statements as the exploit vector. It does not provide specific log entries, indicators of compromise, or detection signatures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203