CVE-2026-76461
Received Received - Intake

Remote Command Execution in Cisco Secure Email Gateway

Vulnerability report for CVE-2026-76461, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
cisco secure_email_gateway 15.5.5-014
cisco secure_email_gateway 16.0.4-302
cisco secure_email_gateway 16.5.0-780

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a critical SQL injection vulnerability in Cisco Secure Email Gateway (AsyncOS Software) that allows unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system. The flaw stems from insufficient validation in the email parsing logic, enabling attackers to send crafted emails containing malicious SQL statements through an affected device.

Detection Guidance

Check Cisco Secure Email Gateway mail logs for suspicious SQL statements such as entries containing 'COPY...TO PROGRAM'. Cross-reference network and firewall logs for unusual activity like unexpected data transfers to external IP addresses.

Impact Analysis

A successful exploit could lead to full system compromise, including data theft, malware installation, or lateral network movement. Attackers may gain root-level access, allowing them to erase evidence or perform unauthorized actions like unexpected data transfers to external IP addresses.

Compliance Impact

This vulnerability could severely impact compliance with GDPR and HIPAA due to the potential for full system compromise, including unauthorized access to sensitive data. Root-level access allows attackers to exfiltrate, alter, or delete data, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Upgrade Cisco Secure Email Gateway to fixed releases like 15.5.5-014, 16.0.4-302, or 16.5.0-780. Restrict appliance access, disable unnecessary services, and implement strong authentication. Cloud-based instances are already updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76461. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart