CVE-2026-76461 is an SQL injection vulnerability in the email-parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. Insufficient validation of crafted email content permits an unauthenticated remote attacker to introduce malicious SQL statements during inbound-message processing. The resulting arbitrary SQL execution can be leveraged to execute operating-system commands as root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An actively exploited SQL injection vulnerability affecting Cisco Secure Email Gateway-related products and Cisco Secure Email and Web Manager. It has been added to CISA's KEV catalog.
A SQL injection vulnerability affecting Cisco AsyncOS for Cisco Secure Email Gateway, Cisco Secure Email Gateway, and Cisco Secure Email and Web Manager. Cisco reported active exploitation, and CISA added it to the KEV catalog.
Critical (CVSS 9.8) unauthenticated remote-code-execution vulnerability in Cisco AsyncOS email-message parsing logic. Improper validation of input parameters allows a remote attacker to send crafted email messages, execute arbitrary SQL instructions, and ultimately run commands as root on the underlying operating system.
A critical unauthenticated remote SQL injection vulnerability (CWE-89) in the email-parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. A crafted email containing malicious SQL statements can enable arbitrary SQL execution and ultimately root-level command execution on the underlying operating system.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.