CISA Adds Critical Cisco Secure Email Gateway Flaw to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-76461, affects Cisco Secure Email Gateway and can be exploited remotely without authentication.
Cisco confirmed the vulnerability is already being exploited in the wild and attackers can send specially crafted emails containing malicious SQL statements to trigger arbitrary command execution on the underlying system with root privileges.
According to CISA's advisory, there are no workarounds that address this issue. The agency orders federal agencies to fix the flaw by September 17, 2026.