Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-76461
Cisco Secure Email Gateway SQL Injection Vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .2827 98.1 YES
AFFECTED
Product Versions Fixed
Cisco Secure Email 14.0.0-698 – —
TIMELINE
Aug 19 Reserved by cisco
Sep 14 ADDED TO KEV — CVE-2026-76461 (Cisco Secure Email). Remediation due September 17, 2026.
Sep 14 Published (CNA: cisco)
Sep 18 DUE DATE PASSED — CVE-2026-76461 (Cisco Secure Email). CISA remediation deadline was September 17, 2026; still in catalog.
Description
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| August 19, 2026 | Reserved | Reserved by cisco |
| September 14, 2026 | KEV ADDED | ADDED TO KEV — CVE-2026-76461 (Cisco Secure Email). Remediation due September 17, 2026. |
| September 14, 2026 | Published | Published (CNA: cisco) |
| September 18, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-76461 (Cisco Secure Email). CISA remediation deadline was September 17, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Cisco | Cisco Secure Email | — | 14.0.0-698 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-76461 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.