This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisco
Cisco asyncos Cisco secure Email Gateway C195 Cisco secure Email Gateway C395 Cisco secure Email Gateway C695 Cisco secure Email Gateway Virtual Appliance C100v Cisco secure Email Gateway Virtual Appliance C300v Cisco secure Email Gateway Virtual Appliance C600v |
|
| CPEs | cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c100v:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c300v:-:*:*:*:*:*:*:* cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c600v:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:secure_email_gateway_c195:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:secure_email_gateway_c395:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:secure_email_gateway_c695:-:*:*:*:*:*:*:* cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cisco
Cisco asyncos Cisco secure Email Gateway C195 Cisco secure Email Gateway C395 Cisco secure Email Gateway C695 Cisco secure Email Gateway Virtual Appliance C100v Cisco secure Email Gateway Virtual Appliance C300v Cisco secure Email Gateway Virtual Appliance C600v |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system. | |
| Title | Cisco Secure Email Gateway SQL Injection Vulnerability | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-09-15T03:56:06.270Z
Reserved: 2026-08-19T12:02:03.637Z
Link: CVE-2026-76461
Updated: 2026-09-14T16:34:06.587Z
Status : Analyzed
Published: 2026-09-14T17:17:51.113
Modified: 2026-09-15T12:47:32.497
Link: CVE-2026-76461
No data.
OpenCVE Enrichment
Updated: 2026-09-15T08:00:16Z