VDB

GCVE-110-NCSC-2026-368

GCVE-110-NCSC-2026-368
Advisory PublishedCVSS 9.8/10
Vulnetix · Advisory published September 14, 2026
A vulnerability in Cisco AsyncOS Software for Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands and SQL statements with root privileges via crafted email parsing exploits due to insufficient validation.

Weaknesses (CWE)

CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Risk Scores

CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Ciscovers:unknown/*

References

advisory
advisory
advisory

Browse GCVE Records

318 records in the GCVE database · Updated September 15, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›