Cisco Patches Critical SQL Injection Flaw in Secure Email Gateway, Exploited in Wild
Cisco released fixes in September 2026 for CVE-2026-76461, a critical SQL injection vulnerability in AsyncOS for its Secure Email Gateway, scoring 9.8 on the CVSS scale. The flaw exists in the inbound mail parsing component, where insufficient input validation allows an unauthenticated remote attacker to execute arbitrary SQL statements and ultimately gain root access on the underlying operating system. Both physical and virtual deployments are affected, with patched builds available at versions 15.5.5-0141, 16.0.4-3021, and 16.5.0-780. Cisco confirmed active exploitation in the wild prior to the patch release, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of 17 September 2026. Beyond upgrading to a fixed build, Cisco advises organizations to audit devices for signs of compromise, rotate credentials, and rebuild any appliance suspected of full compromise, as root-level access cannot be reliably eliminated through a firmware upgrade alone.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in