PT-2026-91270 · Cisco · Asyncos+1

CVE-2026-76461

·

Published

2026-09-14

·

Updated

2026-09-30

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Secure Email Gateway versions prior to 15.5.5-014 Cisco Secure Email Gateway versions prior to 16.0.4-302 Cisco Secure Email Gateway versions prior to 16.5.0-780
Description A critical SQL injection flaw exists in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. An unauthenticated remote attacker can exploit this by sending a specially crafted email containing malicious SQL statements. Successful exploitation allows the attacker to execute arbitrary SQL statements, leading to the execution of arbitrary operating system commands with root privileges. Cisco has confirmed active exploitation of this issue. Because root access allows attackers to remove or conceal evidence on the device, local logs may be unreliable.
Recommendations Update to version 15.5.5-014 or later. Update to version 16.0.4-302 or later. Update to version 16.5.0-780 or later. As a temporary mitigation, restrict access to the management interface to trusted systems and separate mail and management interfaces. For suspected compromises, renew all installed credentials and cryptographic material after applying the fix.

Exploit

Fix

RCE

LPE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14615
CVE-2026-76461

Affected Products

Asyncos
Secure Email Gateway