CVE-2026-76461: Cisco Secure Email Gateway
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
- Vendor
- Cisco
- Product
- Secure Email Gateway
- Vulnerability
- Cisco Secure Email Gateway SQL Injection Vulnerability
- Date added
- Sep 14, 2026
- CISA due date (U.S. federal agencies)
- Sep 17, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-89
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02