CISA KEV Alert 14 Sept 2026, 20:32 UTC

CISA Warns of Actively Exploited Cisco Email Gateway Flaw

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) catalogue on 14 September 2026. The vulnerability affects Cisco Secure Email Gateway and is known as the Cisco Secure Email Gateway SQL Injection Vulnerability. It could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

The flaw exists in Cisco AsyncOS software for Cisco Secure Email Gateway and is a SQL injection vulnerability. An attacker can exploit it remotely without authentication, potentially gaining root-level control of the host operating system. The vulnerability has a CVSS score of 9.8 and is rated Critical. The available data does not confirm whether a patch is available; patch status is listed as unknown.

CISA’s KEV listing confirms active exploitation. The available information does not establish use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 17 September 2026. Organisations should treat internet-exposed Secure Email Gateway systems as a priority for investigation and response.

CISA requires organisations to apply mitigations in accordance with Cisco’s instructions, while following CISA’s BOD 26-04 guidance on prioritising security updates based on risk and its Forensics Triage Requirements. Organisations must follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. FCEB agencies are directly affected, but all organisations should review their exposure, asset internet accessibility and patching status.

See the NVD entry and CISA KEV catalogue for full details.

View CISA KEV Entry

Article by CyberSIXT