SB2026091491 - SQL injection and RCE in Cisco Secure Email Gateway
Published: September 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) SQL injection (CVE-ID: CVE-2026-76461) Exploited
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 10 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
The vulnerability allows a remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
The vulnerability exists due to insufficient validation in the email parsing logic when processing a crafted email message containing malicious SQL statements. A remote attacker can send a crafted email message containing malicious SQL statements to execute arbitrary commands with root privileges on the underlying operating system.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install update from vendor's website.