Critical Cisco Secure Email Gateway flaw CVE-2026-76461 exploited in the wild

Summary
Cisco confirmed active exploitation of critical CVE-2026-76461, an unauthenticated remote SQL injection flaw in Cisco Secure Email Gateway that could enable root-level command execution.
Key points
- CVE-2026-76461 is a SQL injection vulnerability in the email parsing functionality of Cisco AsyncOS Software.
- The flaw has a CVSS score of 9.8 and could let an unauthenticated remote attacker execute arbitrary commands as root.
- Cisco confirmed the vulnerability is being exploited in the wild; CISA added it to the Known Exploited Vulnerabilities catalog.
- Organizations are advised to identify vulnerable Cisco Secure Email Gateway versions and upgrade as appropriate.
- SophosLabs is monitoring related activity and plans to provide detections and protections as available.
Article Details
- Vulnerability Types
- SQL injection
- Severity
- Critical (CVSS 9.8)
- Exploitation Status
- active
- Exploit Availability
- unknown
- Patch Status
- unknown
CVE
Vendors
Products
Cisco AsyncOS Softwareis a critical (CVSS score of 9.8) SQL injection flaw in the email parsing functionality of Cisco AsyncOS Software. Successful exploitation “could allow an unauthenticated, remote attacker to execute arbitraryCisco Secure Email GatewayOn September 14, 2026, Cisco disclosed a vulnerability in Cisco Secure Email Gateway. CVE-2026-76461 is a critical (CVSS score of 9.8) SQL injection flaw in the email parsing functionality of Cisco AsyncOS Software.