CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on t...
Affects 0 products across 1 vendor.
Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.
Show all 6
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical severity vulnerability (CVE-2026-76461) affects the target system. A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability...
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-76461?
What is the CVSS score for CVE-2026-76461?
Is CVE-2026-76461 actively exploited?
How do I remediate CVE-2026-76461?
What systems are affected by CVE-2026-76461?
| CVE ID | CVE-2026-76461 |
|---|---|
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-09-14 |
| Last Modified | 2026-09-15 |
| ICS Relevance | 75% |
| Weakness (CWE) | |
| Source | NVD |
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Fixed Version |
|---|---|---|
| Cisco | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | ● Active Exploitation Confirmed (added 2026-09-14) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
This Vulnerability Is Being Actively Exploited
CVE-2026-76461 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.
Create a free account →