Cisco ESA SQL-to-root command execution (CVE-2026-76461)
Detects the use of 'COPY TO PROGRAM' syntax within Cisco Email Security Appliance (ESA) logs. This pattern is indicative of potential command injection or OS command execution attempts often associated with exploitation of database-related functionalities, specifically targeting Cisco ESA management or backend interfaces.
Microsoft Sentinel (KQL)

