CVE-2026-76461: Cisco Secure Email Gateway
Cisco AsyncOS 소프트웨어는 Cisco Secure Email Gateway (SEG)에 대한 SQL Injection vulnerability를 포함하고, 원격 공격자는 하위 운영 체제에서 루트 권한으로 임의 명령을 실행할 수 있습니다.
CISA (English)
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
- 공급업체
- Cisco
- 제품
- Secure Email Gateway
- 취약점
- Cisco Secure Email Gateway SQL Injection Vulnerability
- 추가일
- 2026. 9. 14.
- CISA 조치 기한(미국 연방기관)
- 2026. 9. 17.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-89
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02