Skip to main content

Cisco Releases Security Advisory for Critical SQL Injection Vulnerability in Secure Email Gateway

Successful exploitation of CVE-2026-76461 could allow an unauthenticated remote attacker to obtain root-level command execution on affected gateways

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-76461 could allow an unauthenticated remote attacker to obtain root-level command execution on affected gateways


Threat details

Exploitation of CVE-2026-76461

Cisco has reported exploitation of CVE-2026-76461. The vulnerability has also been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.

The NHS England National CSOC assesses further exploitation as likely.


Introduction

Cisco has released a security advisory to address a critical vulnerability in Cisco Secure Email Gateway. Successful exploitation of CVE-2026-76461 could allow an unauthenticated remote attacker to obtain root-level command execution on affected gateways.

  • CVE-2026-76461 - SQL Injection vulnerability - CVSS v3.1 Base Score of 9.8

Remediation advice

Affected organisations are encouraged to review the Cisco advisory Cisco Secure Email Gateway SQL Injection Vulnerability (cisco-sa-esa-inj-2bLVGmhX) and apply the relevant update as soon as possible.

Organisations are also encouraged to review the Cisco advisory Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 and take appropriate action.



Last edited: 15 September 2026 2:16 pm