The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system.
“An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device,” Cisco said in a Monday advisory. “A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.”
Ein E-Mail Security Produkt, das SQL Statements aus dem Inhalt von E-Mails ausführt und damit Remote Code Execution ermöglicht?
Ich muss sagen, das ist durchaus eine der kuriosesten Sicherheitslücken dieses Jahr.


