HIGHVulnerability
Verified
Global
CISA KEV: Cisco Secure Email Gateway — Cisco Secure Email Gateway SQL Injection Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Analysis
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-14. Remediation due: 2026-09-17.