注意喚起: Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)に関する注意喚起 (公開)

Imported from official source

Cybersecurity Classified by Officially

I. 概要

Ciscoは、2026年9月15日にCisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)を公表しました。本脆弱性の悪用により、認証されていないリモートの攻撃者が悪意のあるSQL文を含む細工したメールを送信し、脆弱性のある対象システムでメールを受け取ると、対象システム上でroot権限で任意のコマンドが実行される可能性があります。Ciscoは、2026年9月に本脆弱性の悪用を確認しているとのことです。

Cisco Secure Email Gateway SQL Injection Vulnerability

同製品について、JPCERT/CCでは、過去に別の脆弱性(CVE-2025-20393)を悪用した侵害事案が国内で発生していることを確認しています。本脆弱性の影響を受ける製品を利用している場合は、後述「III. 対策」以降に記載の情報を確認の上、対策と侵害調査の実施を検討してください。

II. 対象

本脆弱性の対象となる製品およびバージョンは次のとおりです。詳細は、開発者が提供する最新の情報をご確認ください。

Cisco Secure Email Gateway向けCisco AsyncOSソフトウェア

III. 対策

Ciscoは本脆弱性を修正したバージョンへのアップグレードを推奨しています。詳細は、開発者が提供する最新の情報を確認してください。

V. 侵害調査

Ciscoはアドバイザリ内で脆弱性が悪用された可能性を確認するためのログ調査方法を案内しています。一方、本脆弱性の悪用に成功した攻撃者はroot権限でコマンドを実行できるため、ログや侵害の痕跡が削除されている可能性があるとしています。そのため、Cisco Secure Email Gateway上のログだけでなく、周辺機器などのネットワークログとも突合して調査することが推奨されています。詳細は、開発者が提供する最新の情報を確認してください。

This is an extract. The publication continues at the source.

Read the original at the source: https://www.jpcert.or.jp/at/2026/at260027.html

Officially imported this from JPCERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
JPCERT Coordination Center — imported from official source
Official source
https://www.jpcert.or.jp/rss/jpcert.rdf RSS
Imported
September 18, 2026 11:34
Versions
1 recorded
Identity
https://www.jpcert.or.jp/at/2026/at260027.html

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.