Skip to content
CiscoCVE-2026-76461

Cisco Secure Email: remote code execution

Critical9.8CVE-2026-76461 · Published Sep 14, 2026 · updated Sep 15, 2026

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Secure Email
Product
<= 14.0.0-698No fix yet
<= 13.5.1-277No fix yet
<= 13.0.0-392No fix yet
<= 14.2.0-620No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Identity Services Engine Software: remote code execution
Critical9.9Sep 16
Cisco Secure Email: path traversal
Critical9.8Sep 14
Cisco Secure Email and Web Manager: improper access control
Critical9.8Sep 14
Cisco Secure Email: improper quantity validation
High7.5Sep 14
As part of Cisco's ongoing commitment to proactive security and product quality
Critical9.8Sep 14
As part of Cisco's ongoing commitment to proactive security and product quality
Critical9.8Sep 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.