chiprook
← Security
SecuritySeptember 26, 2026, 09:40

CVE-2026-76461: SQL injection in Cisco email gateway grants root

Cisco patched CVE-2026-76461 in AsyncOS for Secure Email Gateway, rated CVSS 9.8: an unauthenticated attacker can send a crafted email to execute arbitrary SQL and then commands as root. Fixed builds are 15.5.5-0141, 16.0.4-3021 and 16.5.0-780; CISA added the flaw to its Known Exploited Vulnerabilities catalog with a September 17, 2026 deadline.

CVE-2026-76461: SQL injection in Cisco email gateway grants root
#Cisco#AsyncOS#CISA
Read next
Security

Attackers exploit Roundcube SQL injection CVE-2026-48842

Security

Metabase CVE-2026-72898: unauthenticated SQL injection exposes the data warehouse

Security

Cisco FMC SQL injection CVE-2026-20344: monitoring plan

Security

SonicWall SMA1000 Command Injection CVE-2026-83549 Chained to Root