VDB
GCVE-110-NCSC-2026-368
GCVE-110-NCSC-2026-368
Advisory PublishedCVSS 9.8/10
A vulnerability in Cisco AsyncOS Software for Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands and SQL statements with root privileges via crafted email parsing exploits due to insufficient validation.
Weaknesses (CWE)
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Risk Scores
CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Cisco | vers:unknown/* | — | — |
Aliases
Browse GCVE Records
318 records in the GCVE database · Updated September 15, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.