CVE-2026-76461

● KEV CRITICAL

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on t...

Affects 0 products across 1 vendor.

CVSS 3.19.8
EPSS28.3%
Percentile98th
PatchUnknown
KEV Added2026-09-14
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-89: SQL Injection

Attacker inserts SQL commands into application queries through user-controlled input, allowing unauthorized database access.

Related Attack Patterns (CAPEC)
CAPEC-7 Blind SQL Injection
via CWE-89
CAPEC-108 Command Line Execution through SQL Injection
via CWE-89
CAPEC-109 Object Relational Mapping Injection
via CWE-89
CAPEC-110 SQL Injection through SOAP Parameter Tampering
via CWE-89
CAPEC-470 Expanding Control over the Operating System from the Database
via CWE-89
Show all 6
via CWE-89

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical severity vulnerability (CVE-2026-76461) affects the target system. A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-76461?
A critical severity vulnerability (CVE-2026-76461) affects the target system. A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability...
What is the CVSS score for CVE-2026-76461?
CVE-2026-76461 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 28.3%.
Is CVE-2026-76461 actively exploited?
Yes. CVE-2026-76461 is in the CISA KEV catalog (added 2026-09-14). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-76461?
Apply vendor patches for CVE-2026-76461. Monitor Cisco advisories.
What systems are affected by CVE-2026-76461?
CVE-2026-76461 affects: Cisco.
Vulnerability Details
CVE IDCVE-2026-76461
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-09-14
Last Modified2026-09-15
ICS Relevance75%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Cisco — —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 13 Days
CISA KEV● Active Exploitation Confirmed (added 2026-09-14)
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Cisco
CVE-2007-1257 10.0 The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 76... CVE-2009-1167 10.0 Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform... CVE-2011-0364 10.0 The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6... CVE-2011-0382 10.0 The CGI subsystem on Cisco TelePresence Recording Server devices with softwar... CVE-2011-2738 10.0 Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before ...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-76461 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.

Create a free account →