Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
6646 articles · 215552 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-76461KEVEXPLOITED
cis · cisco secure email

Cisco Secure Email Gateway SQL Injection Vulnerability

Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Affected Products

VendorProductVersions
ciscisco secure email14.0.0-698, 13.5.1-277, 13.0.0-392, 14.2.0-620, 13.0.5-007, 13.5.4-038, 14.2.1-020, 14.3.0-032, 15.0.0-104, 15.0.1-030, 15.5.0-048, 15.5.1-055, 15.5.2-018, 16.0.0-050, 15.0.3-002, 16.0.0-054, 15.5.3-022, 16.0.1-017, 15.5.4-012, 16.0.4-016, 15.0.5-016, 16.0.2-112, 16.0.3-044

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

Related News (2 articles)

Tier B
CCCS Canada4h ago
Cisco security advisory (AV26-921)
→ No new info (linked only)
Tier C
VulDB7h ago
CVE-2026-76461 | Cisco AsyncOS up to 16.0.4-016 Email Parsing sql injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-89
PublishedSep 14, 2026
Trending Score138🔥
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Trending: 89
CRITICALCVE-2026-76440
Cisco Secure Email Gateway Security Hardening Release
Trending: 44
CRITICALCVE-2026-76443
Cisco Secure Email Gateway Security Hardening Release
Trending: 44
CRITICALCVE-2026-20353
Cisco Secure Email Gateway Security Hardening Release
Trending: 44
HIGHCVE-2026-20349
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
Trending: 38

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 14, 2026
Added to CISA KEV
Sep 14, 2026
Discovered by ZDM
Sep 14, 2026
Actively Exploited
Sep 14, 2026