Junglewise Threat Intelligence

CVE-2026-76461: Cisco Secure Email Gateway SQL injection

CVE-2026-76461 · Severity: critical · Exploited in the wild · Published 2026-09-14

Executive brief

Cisco Secure Email Gateway is an appliance that filters and monitors email traffic for organizations. A SQL injection vulnerability in the underlying AsyncOS software allows remote attackers without credentials to execute arbitrary commands with full system privileges, potentially giving them complete control over the email gateway and access to all processed emails.

Technical details

The vulnerability exists in Cisco AsyncOS, the core software running Secure Email Gateway appliances. A SQL injection flaw in an unauthenticated, network-accessible component allows remote attackers to inject and execute arbitrary SQL commands. By exploiting this injection point, an attacker can escalate privileges to execute arbitrary operating system commands with root privileges. The vulnerability requires no authentication and is reachable over the network. Confirmed exploitation in the wild indicates active threat activity. Patch availability should be obtained from Cisco's security advisory.

Affected products

  • Cisco Secure Email Gateway <UNKNOWN>

Timeline

  • 2026-09-14: disclosed
  • exploited: confirmed exploitation in the wild

Related threats