Description
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: 28.3% Moderate
KEV: Yes
Impact: Remote code execution with root privileges
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. The parser does not properly validate or sanitize certain email fields, allowing a crafted message to contain malicious SQL statements. When processed, these statements are executed, giving an attacker the ability to run arbitrary commands with root privileges on the operating system that hosts the gateway.

Affected Systems

Cisco Secure Email Gateway, specifically the Cisco AsyncOS Software component. No specific version information is provided in the advisory, so all deployments of the gateway are potentially affected until patched.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, and the vulnerability is listed in the CISA KEV catalog, underscoring its exploitation potential. The EPSS score of 28% suggests a significant likelihood that attackers will exploit this flaw. The attack vector is malicious email to the gateway. Successful exploitation would grant the attacker full control with root rights, potentially affecting confidentiality, integrity, and availability of the protected network.

Generated by OpenCVE AI on September 26, 2026 at 05:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Cisco’s latest Secure Email Gateway patch or firmware update that addresses the SQL injection flaw
  • Upgrade the Cisco AsyncOS Software to the newest supported version to eliminate the vulnerability
  • Limit inbound email traffic to approved, trusted sources or enforce firewall rules to reduce exposure to malicious mail

Generated by OpenCVE AI on September 26, 2026 at 05:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco secure Email
Vendors & Products Cisco secure Email

Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco asyncos
Cisco secure Email Gateway C195
Cisco secure Email Gateway C395
Cisco secure Email Gateway C695
Cisco secure Email Gateway Virtual Appliance C100v
Cisco secure Email Gateway Virtual Appliance C300v
Cisco secure Email Gateway Virtual Appliance C600v
CPEs cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c100v:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c300v:-:*:*:*:*:*:*:*
cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c600v:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_email_gateway_c195:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_email_gateway_c395:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:secure_email_gateway_c695:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco asyncos
Cisco secure Email Gateway C195
Cisco secure Email Gateway C395
Cisco secure Email Gateway C695
Cisco secure Email Gateway Virtual Appliance C100v
Cisco secure Email Gateway Virtual Appliance C300v
Cisco secure Email Gateway Virtual Appliance C600v

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Title Cisco Secure Email Gateway SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

kev

{'dateAdded': '2026-09-14T00:00:00+00:00', 'dueDate': '2026-09-17T00:00:00+00:00'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cisco Asyncos Secure Email Secure Email Gateway C195 Secure Email Gateway C395 Secure Email Gateway C695 Secure Email Gateway Virtual Appliance C100v Secure Email Gateway Virtual Appliance C300v Secure Email Gateway Virtual Appliance C600v
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T12:10:27.392Z

Reserved: 2026-08-19T12:02:03.637Z

Link: CVE-2026-76461

cve-icon Vulnrichment

Updated: 2026-09-14T16:34:06.587Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T17:17:51.113

Modified: 2026-09-15T12:47:32.497

Link: CVE-2026-76461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T05:45:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')