CVE-2026-76461

9.8 CISA KEV

Cisco · Secure Email Gateway

A critical SQL injection vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted email messages.

Executive summary

Cisco Secure Email Gateway is susceptible to a critical remote code execution vulnerability that is currently being actively exploited in the wild.

Vulnerability

This flaw is an SQL injection (CWE-89) within the email parsing logic of Cisco AsyncOS Software. An unauthenticated attacker can send a specially crafted email containing malicious SQL statements to trigger command execution with root-level privileges on the underlying operating system.

Business impact

The severity of this vulnerability is critical, reflected by a CVSS score of 9.8. Successful exploitation grants an attacker full control over the gateway, which facilitates unauthorized access to sensitive communications, potential data exfiltration, and complete system compromise. Given the gateway's role in processing organizational email, this represents a severe risk to both operational integrity and data confidentiality.

Remediation

Immediate Action: Review the official Cisco security advisory at the provided reference link and apply all recommended vendor updates or configuration mitigations immediately.

Proactive Monitoring: Monitor system logs for unusual email parsing errors or suspicious SQL-related activity originating from external mail sources.

Compensating Controls: Ensure that perimeter defenses and email security policies are strictly enforced to filter malformed or suspicious attachments until a permanent patch is verified and deployed.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to confirmed active exploitation and the potential for full system compromise, this vulnerability must be treated as an emergency priority. Administrators should consult the Cisco security advisory immediately to identify the latest patches and apply them without delay, as the ability for unauthenticated attackers to gain root access poses an existential threat to the security of the email infrastructure.

More Cisco CVEs all →

History

  1. Disclosed CVE record published
  2. Added to CISA KEV confirmed active exploitation
  3. Collected by CVE Brief via github
  4. Analyst report written
  5. Published in the daily brief kev section

Sources