{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cisco-asyncos-for-cisco-secure-email-gateway--15.5.5-014--16.0.4-302--16.5.0-780/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-76461"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cisco AsyncOS for Cisco Secure Email Gateway (\u003c 15.5.5-014, \u003c 16.0.4-302, \u003c 16.5.0-780)","Cisco Secure Email Gateway (\u003c 15.5.5-014, \u003c 16.5.0-780)","Cisco Secure Email and Web Manager (\u003c 15.5.5-006, \u003c 16.5.0-429)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","cve","network","active-exploitation"],"_cs_type":"threat","_cs_vendors":["Cisco"],"content_html":"\u003cp\u003eCisco has issued a security advisory regarding a SQL injection vulnerability identified as CVE-2026-76461, which impacts Cisco AsyncOS for Cisco Secure Email Gateway, Cisco Secure Email Gateway, and Cisco Secure Email and Web Manager. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary SQL commands on the underlying database of the affected appliance, potentially leading to unauthorized data exfiltration or system compromise. Cisco reports that this vulnerability is being actively exploited in the wild, and it has been subsequently added to the CISA Known Exploited Vulnerabilities (KEV) Catalog. The flaw necessitates an immediate upgrade to the patched versions provided by the vendor to remediate the exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-76461 allows unauthorized attackers to interact with the backend databases of affected Cisco Secure Email appliances. Given the sensitivity of email security gateways, successful exploitation could lead to the exposure of configuration data, message metadata, or other system information. The inclusion of this CVE in the CISA KEV catalog underscores the high risk of widespread exploitation against organizations utilizing these gateway appliances in their perimeter defenses.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch all affected Cisco products immediately to the recommended versions listed in the vendor advisory: Upgrade Cisco AsyncOS for Cisco Secure Email Gateway to 15.5.5-014, 16.0.4-302, 16.5.0-780 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade Cisco Secure Email Gateway to version 15.5.5-014, 16.5.0-780 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade Cisco Secure Email and Web Manager to 15.5.5-006, 16.5.0-429 or later.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs on these appliances for anomalous HTTP requests containing SQL syntax (e.g., SELECT, UNION, SLEEP) targeting administrative or API endpoints.\u003c/li\u003e\n\u003cli\u003eReview the official Cisco security advisory (cisco-sa-esa-inj-2bLVGmhX) for further technical details and guidance.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-15T07:02:16Z","date_published":"2026-09-15T07:02:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cisco-sql-injection/","summary":"Cisco has confirmed active exploitation of a SQL injection vulnerability (CVE-2026-76461) affecting multiple versions of Cisco Secure Email Gateway and Secure Email and Web Manager products.","title":"Active Exploitation of SQL Injection in Cisco Secure Email Gateway","url":"https://feed.craftedsignal.io/briefs/2026-09-cisco-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cisco AsyncOS for Cisco Secure Email Gateway (\u003c 15.5.5-014, \u003c 16.0.4-302, \u003c 16.5.0-780)","version":"https://jsonfeed.org/version/1.1"}