CVE-2026-76461 in Cisco Secure Email Gateway is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-09-14). Required action, remediation due date, ransomware association, EPSS score and vendor advisories.
CVE-2026-76461 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added 2026-09-14. Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Wording published by CISA for this catalog entry. It is the baseline action, not a decision about your environment: whether this exposure matters for you depends on where the affected component runs, what it is exposed to and who owns it.
A catalog entry tells you a vulnerability is being exploited somewhere. It does not tell you whether it matters in your estate, who owns the fix, or what evidence an auditor will ask for later. That is the work VulnTrek does: it takes findings from the tools you already run, decides which exposure actually matters, routes it to an owner, keeps remediation human-approved and retains the lineage as evidence.
Sourced from public upstream advisories (CISA KEV, ENISA EUVD, vendor PSIRTs) mirrored daily. Informational only — not a remediation decision, not legal advice, and the absence of a record is not evidence of safety.