The Appliance That Reads Every Email Is Now an Unauthenticated Root Shell
The SQL Injection in Email Parsing The vulnerability identified as CVE-2026-76461 is a failure in the email parsing logic of Cisco Secure Email Gateway appliances. Not the web management interface – the core engine that processes inbound mail. Cisco’s advisory describes a CWE-89 SQL injection that allows an unauthenticated, remote attacker to execute arbitrary commands…