Skip to content
ThreatCluster

Cisco Secure Email Gateway SQL Injection Vulnerability Disclosed

First seen 14 Sep 2026, 17:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 18:57 UTC
  • Cisco Secure Email Gateway has a critical SQL injection vulnerability (CVE-2026-76440).
  • Exploitation allows remote attackers to execute commands with root privileges.
  • Cisco has released patches; no workarounds are available.

A critical SQL injection vulnerability has been identified in Cisco AsyncOS Software for the Cisco Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This issue stems from insufficient validation in the email parsing logic, enabling exploitation through crafted email messages containing malicious SQL statements. Cisco has released software updates to address this vulnerability, with no workarounds available. The vulnerability affects both physical and virtual instances of the Cisco Secure Email Gateway. Additionally, a security hardening release has been issued for both the Cisco Secure Email Gateway and the Secure Email and Web Manager, addressing multiple vulnerabilities, one of which is actively exploited. Cisco has grouped these vulnerabilities under common weakness enumerations (CWE) and assigned CVE identifiers. The vulnerabilities have been confirmed to affect specific software releases, and Cisco has provided guidance on identifying potential exploitation attempts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-14
Cisco Secure Email Gateway SQL Injection Vulnerability disclosed
Cisco announced a critical SQL injection vulnerability in its Secure Email Gateway, allowing root command execution via crafted emails.
Sec.Cloudapps.Cisco
2026-09-14
Cisco Secure Email Gateway and Secure Email and Web Manager hardening release
Cisco released updates for Secure Email Gateway and Secure Email and Web Manager addressing multiple vulnerabilities, including one actively exploited.
Sec.Cloudapps.Cisco
2026-09-14
CVE-2026-76440 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-76441 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-20353 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-76442 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-14
CVE-2026-76443 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-20353 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed