<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cisco AsyncOS for Cisco Secure Email Gateway (&lt; 15.5.5-014, &lt; 16.0.4-302, &lt; 16.5.0-780) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/cisco-asyncos-for-cisco-secure-email-gateway--15.5.5-014--16.0.4-302--16.5.0-780/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 07:02:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/cisco-asyncos-for-cisco-secure-email-gateway--15.5.5-014--16.0.4-302--16.5.0-780/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Active Exploitation of SQL Injection in Cisco Secure Email Gateway</title><link>https://feed.craftedsignal.io/briefs/2026-09-cisco-sql-injection/</link><pubDate>Tue, 15 Sep 2026 07:02:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cisco-sql-injection/</guid><description>Cisco has confirmed active exploitation of a SQL injection vulnerability (CVE-2026-76461) affecting multiple versions of Cisco Secure Email Gateway and Secure Email and Web Manager products.</description><content:encoded><![CDATA[<p>Cisco has issued a security advisory regarding a SQL injection vulnerability identified as CVE-2026-76461, which impacts Cisco AsyncOS for Cisco Secure Email Gateway, Cisco Secure Email Gateway, and Cisco Secure Email and Web Manager. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary SQL commands on the underlying database of the affected appliance, potentially leading to unauthorized data exfiltration or system compromise. Cisco reports that this vulnerability is being actively exploited in the wild, and it has been subsequently added to the CISA Known Exploited Vulnerabilities (KEV) Catalog. The flaw necessitates an immediate upgrade to the patched versions provided by the vendor to remediate the exposure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-76461 allows unauthorized attackers to interact with the backend databases of affected Cisco Secure Email appliances. Given the sensitivity of email security gateways, successful exploitation could lead to the exposure of configuration data, message metadata, or other system information. The inclusion of this CVE in the CISA KEV catalog underscores the high risk of widespread exploitation against organizations utilizing these gateway appliances in their perimeter defenses.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch all affected Cisco products immediately to the recommended versions listed in the vendor advisory: Upgrade Cisco AsyncOS for Cisco Secure Email Gateway to 15.5.5-014, 16.0.4-302, 16.5.0-780 or later.</li>
<li>Upgrade Cisco Secure Email Gateway to version 15.5.5-014, 16.5.0-780 or later.</li>
<li>Upgrade Cisco Secure Email and Web Manager to 15.5.5-006, 16.5.0-429 or later.</li>
<li>Monitor web access logs on these appliances for anomalous HTTP requests containing SQL syntax (e.g., SELECT, UNION, SLEEP) targeting administrative or API endpoints.</li>
<li>Review the official Cisco security advisory (cisco-sa-esa-inj-2bLVGmhX) for further technical details and guidance.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>cve</category><category>network</category><category>active-exploitation</category></item></channel></rss>