CVE-2026-76461

Published Sep 14, 2026

Last updated 5 hours ago

Overview

Description
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Source
psirt@cisco.com
NVD status
Undergoing Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Cisco Secure Email Gateway SQL Injection Vulnerability
Exploit added on
Sep 14, 2026
Exploit action due
Sep 17, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@cisco.com
CWE-89

Social media

Hype score
Not currently trending
  1. Cisco Secure Email Gateway zero-day CVE-2026-76461: crafted email -> root RCE on AsyncOS. Actively exploited. No workaround. Patch physical and virtual appliances now. #CyberSecurity #EmailSecurity #CVE Link: https://t.co/8UNF1md9C1

    @Orion84x

    15 Sept 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  2. 🚨 CRITICAL: CVE-2026-76461 - Cisco Secure Email Gateway SQL injection allows unauthenticated remote attackers to execute arbitrary commands with root privileges. Listed on CISA KEV - patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/YGNHsN83qY

    @DFIR_Lab

    15 Sept 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔒 #CyberSecurity CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Added to CISA KEV — De… "On September 14, 2026, CISA added CVE-2026-76461 — a SQL injection vulnerability in Cisco…" 🔗 https://t.co/AyxbY1NBQ4 #CyberSecurity #ThreatIntel #critical #zeroda

    @SecurityAr58409

    15 Sept 2026

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔒 #CyberSecurity CVE-2026-76461: Cisco Secure Email Gateway SQL Injection Added to CISA KEV — De… "On September 14, 2026, CISA added CVE-2026-76461 to the Known Exploited…" 🔗 https://t.co/EkOCUWXrz2 #CyberSecurity #ThreatIntel #cve202676461 #critical #cisakev

    @SecurityAr58409

    15 Sept 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Signal — Cisco Secure Email Gateway, 14 Sep 2026 Cisco disclosed CVE-2026-76461, a CVSS 9.8 flaw under active exploitation. A crafted email can reach unauthenticated root command execution on the appliance. No user click is required. 1/8

    @H1DR4_agent

    15 Sept 2026

    170 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. ・CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability https://t.co/vQqe0gaDmG 『(直訳)Cisco Secure Email Gateway 用の Cisco AsyncOS https://t.co/PpNv5QEgb1

    @taku888infinity

    14 Sept 2026

    1206 Impressions

    1 Retweet

    3 Likes

    3 Bookmarks

    2 Replies

    0 Quotes

  7. Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) Threat Advisory A critical SQL injection flaw in Cisco Secure Email Gateway (CVE-2026-76461) allows unauthenticated remote attackers to execute root… Full write-up → link in bio #cybersecurity #infosec #cve #kev #cis

    @HotaSamit

    14 Sept 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CVE-2026-76461 — CRITICAL — actively exploited per CISA KEV Cisco Secure Email Gateway CVSS 9.8 #Cisco #CVE https://t.co/Ce6MTbdakG

    @threatpodium

    14 Sept 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 Cisco Secure Email Gateway'de 2 yeni güvenlik açığı! Cisco Secure Email Gateway ve Secure Email and Web Manager ürünlerinde CVE-2026-76461 ve CVE-2026-20353 numaralı güvenlik açıkları yayınlandı. 🔴 CVE-2026-76461 — CVSS 9.8 AsyncOS'taki kritik SQL Inject

    @ridvanyagli

    14 Sept 2026

    335 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes