PatchDayAlert

CVE

CVE-2026-76461

0field notes · 1digest CVSS 9.8

The verdict

This is a bad one. An unauthenticated attacker can send a crafted email through your Cisco Secure Email Gateway, exploit an input validation gap in the email parser, and land root-level command execution on the underlying OS via SQL injection. No credentials needed, no user interaction, just a poisoned email flowing through the gateway. CVSS 9.8.

Patch urgency · Patch immediately


Daily digests