Arbitrary Command Execution Vulnerability in Cisco Secure Email Gateway
CVE-2026-76461

9.8CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
14 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-76461?

A vulnerability in the email parsing functionality of Cisco Secure Email Gateway can be exploited by unauthenticated remote attackers. The issue stems from inadequate validation within the email parsing logic, allowing attackers to send specially crafted emails containing harmful SQL statements. If successfully executed, this could grant the attacker the ability to run arbitrary commands with root privileges on the operating system, posing significant risks to system integrity and security.

Affected Version(s)

Cisco Secure Email 14.0.0-698

Cisco Secure Email 13.5.1-277

Cisco Secure Email 13.0.0-392

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.