Cisco Secure Email Gateway SQL Injection Vulnerability
SQL injection in Cisco AsyncOS for Secure Email Gateway lets an unauthenticated remote attacker execute arbitrary OS commands with root privileges. CISA KEV since Sept. 14.
- Vendor
- Cisco
- Product
- Secure Email Gateway
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
A SQL injection vulnerability in Cisco AsyncOS for Cisco Secure Email Gateway (SEG) allows an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. No credentials or prior access are required; the attack vector is network-accessible.
CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 14, 2026, with a remediation deadline of September 17, 2026 for federal agencies under BOD 26-04. Cisco has published mitigation guidance; organizations should apply vendor mitigations immediately and consult the NVD record for advisory references.
