Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, remote code execution and cross-site scripting on the targeted system.
CVE-2026-76461 is being exploited in the wild. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Security Restriction Bypass
Elevation of Privilege
System / Technologies affected
Cisco Secure Email and Web Manager
Cisco Secure Email Gateway (both physical and virtual)
For affected versions, please refer to the link issued by the vendor:
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
