Skip to content
Threat Feed
critical threat exploited

Active Exploitation of Cisco Secure Email Gateway SQL Injection

CISA has added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation of a SQL injection vulnerability in Cisco Secure Email Gateway.

CVE search metadata

CVE search record: CVE-2026-76461. Severity: critical. CVSS: 9.8. KEV: no. Product: Secure Email Gateway. Brief: Active Exploitation of Cisco Secure Email Gateway SQL Injection. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-seg-sql-injection/

CISA has formally added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) Catalog, signaling confirmed active exploitation of Cisco Secure Email Gateway appliances. This vulnerability is classified as a SQL injection flaw, allowing unauthenticated attackers to execute arbitrary SQL commands against the appliance's database backend. Given the critical position of the Secure Email Gateway in an organization's perimeter, successful exploitation grants threat actors potential administrative control, the ability to intercept email communications, and a foothold for lateral movement into the internal network. Organizations utilizing Cisco Secure Email Gateway must prioritize patching immediately, as this vulnerability is currently being leveraged by malicious actors.

Impact

Successful exploitation of CVE-2026-76461 results in unauthorized access to the Cisco Secure Email Gateway, allowing attackers to bypass authentication controls, exfiltrate sensitive mail traffic, or modify appliance configurations. As this is a critical perimeter security component, compromise typically leads to total loss of confidentiality for organizational email and facilitates further network infiltration. The vulnerability poses a high risk to all enterprises that expose these management interfaces to the internet.

Recommendation

Prioritize remediation of CVE-2026-76461 by applying the latest security patches provided by Cisco for the Secure Email Gateway. Conduct a forensic review of system logs to determine if the appliance was accessed or compromised prior to the application of security patches, as required by the guidance in BOD 26-04. Monitor the perimeter for abnormal SQL traffic patterns originating from or directed toward the email gateway management interfaces.


Immediate actions

Patch Cisco Secure Email Gateway to the latest version to mitigate CVE-2026-76461

IT Operations 24h

Mitigations

Apply vendor-supplied security patches to all internet-facing Cisco Secure Email Gateway appliances

immediate IT Operations

CVE-2026-76461