CVE-2026-76461: SQL injection in Cisco email gateway grants root
Cisco patched CVE-2026-76461 in AsyncOS for Secure Email Gateway, rated CVSS 9.8: an unauthenticated attacker can send a crafted email to execute arbitrary SQL and then commands as root. Fixed builds are 15.5.5-0141, 16.0.4-3021 and 16.5.0-780; CISA added the flaw to its Known Exploited Vulnerabilities catalog with a September 17, 2026 deadline.
- CVSS 9.8: SQL injection in the AsyncOS inbound mail parser
- Unauthenticated attack leads to command execution as root
- Fixed builds: 15.5.5-0141, 16.0.4-3021, 16.5.0-780
- CISA sets September 17, 2026 federal remediation deadline
Read next
Security