CVE-2026-76461: Cisco Secure Email Gateway
Cisco AsyncOS 軟體為 Cisco Secure Email Gateway (SEG) 包含一個 SQL 注射漏洞,可以允許一個未經認證的遠端攻擊者在基礎作業系統上執行自願命令的根特權。
CISA (English)
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
- 廠商
- Cisco
- 產品
- Secure Email Gateway
- 漏洞
- Cisco Secure Email Gateway SQL Injection Vulnerability
- 加入日期
- 2026年9月14日
- CISA 修補期限(美國聯邦機關)
- 2026年9月17日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-89
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02