RaqibCTI
CVE

CVE-2026-76461

P2
Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco · Secure Email Gateway
Date added (CISA)
2026-09-14
Remediation due
2026-09-17
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • Void Manticore (Storm-0842) · SparrowDoorcampaignCorrelated cluster2026-09-21

Description

Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

Source: NVD ↗ · CISA KEV Catalog ↗