CISA_KEV · SEPTEMBER 2026 · CONFIRMED

Cisco Secure Email Gateway SQL Injection Vulnerability Exploited

Severity
HIGH
Affected component
cisco secure email gateway (other)
Patched version
Not yet available
CVE-2026-76461

Cisco Secure Email Gateway (SEG) has a critical SQL injection vulnerability that allows remote command execution with root privileges. This vulnerability is actively exploited in the wild.

What happened

Cisco Secure Email Gateway (SEG) software contains a SQL injection vulnerability tracked as CVE-2026-76461. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. The vulnerability was first flagged on September 14, 2026, and confirmed on the same day. It has a CVSS score of 9.8, indicating a critical severity level.

The vulnerability has been exploited in the wild, as confirmed by multiple independent sources including CISA and The Hacker News. The exploit allows attackers to gain full control over the affected systems, making it a high-severity threat. Users of Cisco Secure Email Gateway should assess their exposure and apply recommended mitigations immediately.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If cisco secure email gateway is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Cisco Secure Email Gateway (SEG), you may be affected. Consult the primary sources for the latest information on affected versions.

What should I do right now?

Contact Cisco for patches and mitigations for CVE-2026-76461. Review your system logs and implement network segmentation as interim measures.

Has this been exploited in the wild?

Yes, this vulnerability has been exploited in the wild. It is critical to apply mitigations immediately.

Sources

Join the 0Day waitlist →

← Back to all threats