CVE-2026-76461 PUBLISHED

Cisco Secure Email Gateway SQL Injection Vulnerability

Assigner: cisco
Reserved: 19.08.2026 Published: 14.09.2026 Updated: 15.09.2026

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Cisco
Product Cisco Secure Email
Versions Default: unknown
  • Version 14.0.0-698 is affected
  • Version 13.5.1-277 is affected
  • Version 13.0.0-392 is affected
  • Version 14.2.0-620 is affected
  • Version 13.0.5-007 is affected
  • Version 13.5.4-038 is affected
  • Version 14.2.1-020 is affected
  • Version 14.3.0-032 is affected
  • Version 15.0.0-104 is affected
  • Version 15.0.1-030 is affected
  • Version 15.5.0-048 is affected
  • Version 15.5.1-055 is affected
  • Version 15.5.2-018 is affected
  • Version 16.0.0-050 is affected
  • Version 15.0.3-002 is affected
  • Version 16.0.0-054 is affected
  • Version 15.5.3-022 is affected
  • Version 16.0.1-017 is affected
  • Version 15.5.4-012 is affected
  • Version 16.0.4-016 is affected
  • Version 15.0.5-016 is affected
  • Version 16.0.2-112 is affected
  • Version 16.0.3-044 is affected

Exploits

In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.

References

Problem Types

  • Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') cwe