SQL injection in Secure Email Gateway - CVE-2026-76461

 

SQL injection in Secure Email Gateway - CVE-2026-76461

Published: September 14, 2026


Vulnerability identifier: #VU149711
CSH Severity: Critical
CVSS v4: 10 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-76461
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

The vulnerability exists due to insufficient validation in the email parsing logic when processing a crafted email message containing malicious SQL statements. A remote attacker can send a crafted email message containing malicious SQL statements to execute arbitrary commands with root privileges on the underlying operating system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Secure Email Gateway

How to mitigate CVE-2026-76461

Install security update from vendor's website.

Secure Email Gateway - addressed in versions 15.5.5-014, 16.0.4-302, 16.5.0-780

External References

Related Security Bulletins