THREAT OPS › CVEs › CVE-2026-76461
CVE-2026-76461 — Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Vulnerability details
- Affected productsSecure Email Gateway
- KEV remediation due2026-09-17
Related reporting
- CVE-2026-76461: Cisco Email Gateway Flaw Exploitedsocradar_blog
- CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wildrapid7
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Executionthehackernews
- Cisco security advisory (AV26-921)cccs_ca
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories
- [CISA KEV] CVE-2026-76461 — Cisco Secure Email Gateway: Cisco Secure Email Gateway SQL Injection Vulnerabilitycisa_kev
- Cisco Secure Email Gateway SQL Injection Vulnerabilitycisco_psirt