CISA Adds Cisco Secure Email Gateway SQLi to Known Exploited Vulnerabilities
CISA has listed CVE-2026-76461, a SQL injection flaw in Cisco Secure Email Gateway, as actively exploited and requires urgent remediation by federal agencies.
Tag
5 results in the archive.
CISA has listed CVE-2026-76461, a SQL injection flaw in Cisco Secure Email Gateway, as actively exploited and requires urgent remediation by federal agencies.
ServiceNow fixed four security flaws in its AI Platform, including three critical CVSS 10.0 vulnerabilities that allow unauthenticated code execution and SQL injection.
A critical zero-day SQL injection vulnerability in Metabase has been exploited to breach customer instances, impacting Framework and Tally by enabling data theft.
An Oracle database SQL injection vulnerability was exploited to compile and run the Khunt post-exploitation toolkit entirely within the database engine, avoiding writing executables to disk.
A critical SQL injection vulnerability identified as CVE-2026-63030 affects WordPress Core and is actively exploited, allowing unauthenticated remote code execution.