CVE-2026-76461
published 2026-09-14CVE-2026-76461: A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute…
PriorityP199critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-17
Exploited in the wild
EPSS
28.27%
98.1th percentile
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | < 15.5.5-014 | 15.5.5-014 |
| cisco | asyncos | >= 16.0 < 16.0.4-302 | 16.0.4-302 |
| cisco | asyncos | >= 16.5 < 16.5.0-780 | 16.5.0-780 |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco AsyncOS up to 16.0.4-016 Email Parsing sql injection
vuldb·2026-09-15·CVSS 9.8
CVE-2026-76461 [CRITICAL] Cisco AsyncOS up to 16.0.4-016 Email Parsing sql injection
A vulnerability identified as critical has been detected in Cisco AsyncOS. Affected by this vulnerability is an unknown functionality of the component Email Parsing. The manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-76461. The attack can be initiated remotely. Additionally, an exploit exists.
You should upgrade the affected component.
GHSA
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the
ghsa_unreviewed·2026-09-14
CVE-2026-76461 [CRITICAL] CWE-89 A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
VulnCheck
Cisco Secure Email Gateway SQL Injection Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-76461 [CRITICAL] CWE-89 Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Affected: Cisco Secure Email Gateway
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adhe
CISA
Cisco Secure Email Gateway SQL Injection Vulnerability
cisa·2026-09-14·CVSS 9.8
CVE-2026-76461 [CRITICAL] CWE-89 Cisco Secure Email Gateway SQL Injection Vulnerability
Vulnerability: Cisco Secure Email Gateway SQL Injection Vulnerability
Affected: Cisco Secure Email Gateway
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and
No detection rules found.
No public exploits indexed.
Checkpoint
21st September – Threat Intelligence Report
blogs_checkpoint·2026-09-21
CVE-2026-91843 21st September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, including names and contact details belonging to government officials and contractors, while financial i
Hackernews
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
blogs_hackernews·2026-09-17·CVSS 10.0
CVE-2026-76460 [CRITICAL] Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.
The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.
"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthoriz
Rapid7
CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
blogs_rapid7·2026-09-15·CVSS 9.8
CVE-2026-76461 [CRITICAL] CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
## Overview
On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance.
Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authe
Hackernews
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
blogs_hackernews·2026-09-15·CVSS 9.8
CVE-2026-76461 [CRITICAL] Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-76461 , carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system.
"An attacker could exploit this vulnerability by sending a crafte
2026-09-14
Published
2026-09-14
Added to CISA KEV
Exploited in the wild