critical Known exploitedREV. 01

CVE-2026-76461Cisco Secure Email Gateway — SQL Injection in Email Parsing to Root RCE

Cisco AsyncOS on Secure Email Gateway does not properly validate email content it parses. An attacker can send a crafted email carrying SQL statements through the device to run arbitrary SQL and then commands as root on the appliance, with no login required.

YOUR NEXT MOVE

Apply the mitigations in Cisco advisory cisco-sa-esa-inj-2bLVGmhX to every Secure Email Gateway now; it is exploited in the wild, so check exposed appliances for compromise.

Read the risk

THE VITAL STATS
CVSS score
9.8/ 10
CVSS v3.1
EPSS probability
2%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2026-09-14
Added to KEV
2026-09-14
Exploit published
Not recorded
Confidence
high
Kill chain
initial access
MITRE ATT&CK
T1190, T1059
Severity
critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attacker needsAbility to send an email through an affected Secure Email Gateway appliance; no credentials or user interaction needed

Behind the card

3 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-09-20scrty-crds-pipeline/0.1high
exploitation.known_exploited, exploitation.kev_addedcisa.gov2026-09-20scrty-crds-pipeline/0.1high
epssapi.first.org2026-09-20scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-09-20claude-codehigh
title, exploitation.prerequisitesnvd.nist.gov2026-09-20humanhigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2026-76461 · CRDS 0.1 · Issued 2026-09-20