๐Ÿ”ด CVE-2026-76461

CVE-2026-76461 is a critical (CVSS 9.8) SQL injection vulnerability in Cisco Secure Email Gateway (SEG) AsyncOS software that allows an unauthenticated remote attacker to execute arbitrary commands with root privileges by sending a specially crafted email message. No authentication, user interaction, or prior access is required โ€” the attack vector is the SMTP email processing pipeline itself, which is inherently internet-facing by design. Active exploitation has been confirmed by Cisco PSIRT and the vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog.

โ† Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 โ€” Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-14

Added to CISA KEV: 2026-09-14 0 DAY BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence (Kagi ยท 2026-09-14)

Summary

CVE-2026-76461 is a critical SQL injection vulnerability residing in the email parsing logic of Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) . This flaw allows an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system by sending a specially crafted email . Given its severity (CVSS 9.8) and the ability to gain full system control, it poses a severe threat to organizations relying on this gateway for perimeter security .

Exploitation

  • Active Exploitation: There are reports of active exploitation of this vulnerability in the wild .
  • CISA Status: The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its list of Known Exploited Vulnerabilities (KEV) .
  • Threat Actors: While specific threat actors or ransomware campaigns are not currently named, the nature of the exploit and its status as a widely targeted vulnerability suggest high-level malicious interest.
  • Attack Prerequisites: The attack can be performed remotely by an unauthenticated attacker, does not require user interaction, and leverages crafted email messages to trigger the vulnerability .

Affected Products & Patches

  • Affected Products: Cisco Secure Email Gateway (SEG) running vulnerable versions of Cisco AsyncOS software .
  • Patches/Hotfixes: Users are advised to monitor official Cisco security advisories for patch availability and apply updates immediately.
  • Mitigations: Organizations should restrict access to the management interface and verify email filtering configurations to identify potentially malicious input patterns.

Impact

  • Access/Capabilities: Successful exploitation grants the attacker full root-level command execution on the underlying operating system of the appliance .
  • Business Risk: For internet-facing deployments, this vulnerability allows attackers to gain an initial foothold, bypass perimeter security, potentially exfiltrate sensitive email traffic, or pivot deeper into the internal corporate network, leading to full system compromise.