Cisco Releases Security Advisory for Critical SQL Injection Vulnerability in Secure Email Gateway
Successful exploitation of CVE-2026-76461 could allow an unauthenticated remote attacker to obtain root-level command execution on affected gateways
Summary
Successful exploitation of CVE-2026-76461 could allow an unauthenticated remote attacker to obtain root-level command execution on affected gateways
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-76461
Cisco has reported exploitation of CVE-2026-76461. The vulnerability has also been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses further exploitation as likely.
Introduction
Cisco has released a security advisory to address a critical vulnerability in Cisco Secure Email Gateway. Successful exploitation of CVE-2026-76461 could allow an unauthenticated remote attacker to obtain root-level command execution on affected gateways.
- CVE-2026-76461 - SQL Injection vulnerability - CVSS v3.1 Base Score of 9.8
Remediation advice
Affected organisations are encouraged to review the Cisco advisory Cisco Secure Email Gateway SQL Injection Vulnerability (cisco-sa-esa-inj-2bLVGmhX) and apply the relevant update as soon as possible.
Organisations are also encouraged to review the Cisco advisory Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 and take appropriate action.
Definitive source of threat updates
Last edited: 15 September 2026 2:16 pm