Critical Cisco Secure Email Gateway flaw CVE-2026-76461 exploited in the wild

· Original article ↗

Summary

Cisco confirmed active exploitation of critical CVE-2026-76461, an unauthenticated remote SQL injection flaw in Cisco Secure Email Gateway that could enable root-level command execution.

Key points

  • CVE-2026-76461 is a SQL injection vulnerability in the email parsing functionality of Cisco AsyncOS Software.
  • The flaw has a CVSS score of 9.8 and could let an unauthenticated remote attacker execute arbitrary commands as root.
  • Cisco confirmed the vulnerability is being exploited in the wild; CISA added it to the Known Exploited Vulnerabilities catalog.
  • Organizations are advised to identify vulnerable Cisco Secure Email Gateway versions and upgrade as appropriate.
  • SophosLabs is monitoring related activity and plans to provide detections and protections as available.

Article Details

Vulnerability Types
  • SQL injection
Severity
Critical (CVSS 9.8)
Exploitation Status
active
Exploit Availability
unknown
Patch Status
unknown

CVE

Vendors

Products