What is CVE-2026-76461?
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Timeline
- 2026-09-14Published to the U.S. National Vulnerability Database (NVD)
- 2026-09-14Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-09-15NVD record last updated
- 2026-09-17CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
Cisco Secure Email Gateway SQL Injection Vulnerability
Affected product
Cisco Secure Email Gateway
Remediation Steps
- Check Cisco security advisories for affected product versions
- Apply the vendor security patch as published by Cisco
- Test patched systems in a non-production environment before enterprise deployment
- Monitor for exploitation indicators post-patch
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 2 of September 2026 (September 14 – 20)
Browse all tracked CVEs in the defend.network CVE database →