CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability

Published Sep 14, 2026
·
Updated

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Event History

Sep 14, 2026
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An unauthenticated remote attacker can exploit it by sending a crafted email message through an affected Cisco Secure Email Gateway device. No prior access or user interaction is described as necessary.

2

What level of access could a successful attacker obtain?

Successful exploitation can allow arbitrary SQL statements to be executed and can lead to arbitrary command execution with root privileges on the underlying operating system.

3

What should defenders look for to identify exploitation attempts?

The provided information identifies crafted email messages containing malicious SQL statements as the exploit vector. It does not provide specific log entries, indicators of compromise, or detection signatures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203