Cisco Secure Email Gateway SQLi via SMTP COPY TO PROGRAM (CVE-2026-76461)
Detects potential SQL injection attempts targeting Cisco AsyncOS Email Gateways via the SMTP DATA command. The rule monitors for malicious patterns, specifically those attempting to execute unauthorized commands or database queries (such as COPY TO PROGRAM or embedded SQL statements) within SMTP traffic.
Suricata

