SQL injection in Secure Email Gateway - CVE-2026-76461
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
The vulnerability exists due to insufficient validation in the email parsing logic when processing a crafted email message containing malicious SQL statements. A remote attacker can send a crafted email message containing malicious SQL statements to execute arbitrary commands with root privileges on the underlying operating system.
Note, the vulnerability is being actively exploited in the wild.