CVE-2026-76461

CVSS 9.8 · CRITICAL
EPSS p80
Higher than 80% of all CVEs — elevated exploitation risk.
Patch available
Vendor advisory or patch linked

Published 9/14/2026 · updated 9/15/2026 · CWE-89

Share
Get asset-aware triage

Summary

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

CVSS 9.8 — CRITICAL

9.8 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope unchanged
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS exploitation probability

2.0%

Percentile p80 — Higher than 80% of all CVEs — elevated exploitation risk.

Affected products

1 vendor/product entries
  • Cisco Asyncos< 15.5.5-014
Do you run any of these? Sign in to match this CVE against your SBOM and asset inventory automatically.

Timeline

  1. Sep 14, 2026 · Disclosed / published in NVD
  2. Sep 15, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 8 days ago
  • CVE.org· 8 days ago
  • FIRST EPSS· 8 days ago
  • CISA KEV· no data
  • OSV· 8 days ago

References

Unlock the full report

See how CVE-2026-76461 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.