CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7270

As cited

Copy frozen at (site build).

vulnerabilities

NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway

Cisco patched a vulnerability in Secure Email Gateway caused by insufficient validation of incoming email messages in AsyncOS Software. An unauthenticated attacker can send a specially crafted email containing malicious SQL instructions to execute arbitrary SQL commands and subsequently gain root-level command execution on the underlying operating system. Active exploitation has been observed in the wild.

Why it matters: Organizations running Cisco Secure Email Gateway must apply this patch urgently and audit systems for signs of compromise, as exploitation is already occurring.

VendorsCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway

Cisco patched a vulnerability in Secure Email Gateway caused by insufficient validation of incoming email messages in AsyncOS Software. An unauthenticated attacker can send a specially crafted email containing malicious SQL instructions to execute arbitrary SQL commands and subsequently gain root-level command execution on the underlying operating system. Active exploitation has been observed in the wild.

Why it matters: Organizations running Cisco Secure Email Gateway must apply this patch urgently and audit systems for signs of compromise, as exploitation is already occurring.

VendorsCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway

Cisco patched a vulnerability in Secure Email Gateway caused by insufficient validation of incoming email messages in AsyncOS Software. An unauthenticated attacker can send a specially crafted email containing malicious SQL instructions to execute arbitrary SQL commands and subsequently gain root-level command execution on the underlying operating system. Active exploitation has been observed in the wild.

Why it matters: Organizations running Cisco Secure Email Gateway must apply this patch urgently and audit systems for signs of compromise, as exploitation is already occurring.

VendorsCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gateway

Cisco patched a vulnerability in Secure Email Gateway caused by insufficient validation of incoming email messages in AsyncOS Software. An unauthenticated attacker can send a specially crafted email containing malicious SQL instructions to execute arbitrary SQL commands and subsequently gain root-level command execution on the underlying operating system. Active exploitation has been observed in the wild.

Why it matters: Organizations running Cisco Secure Email Gateway must apply this patch urgently and audit systems for signs of compromise, as exploitation is already occurring.

VendorsCisco
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary