Cisco disclosed active exploitation of CVE-2026-76461, an SQL injection flaw affecting Cisco Secure Email Gateway deployments. The vulnerability affects unpatched releases of Cisco AsyncOS for Cisco Secure Email Gateway, Cisco Secure Email Gateway, and Cisco Secure Email and Web Manager.
CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities Catalog, while the Canadian Centre for Cyber Security issued advisory AV26-921. Cisco has released a September 2026 security-hardening update; administrators should identify affected appliances and management systems and apply Cisco’s prescribed fixed releases promptly.

See which actors are running it and whether you're in range.
20 events from the most recent confirmed update back to the earliest known activity.
Cisco disclosed CVE-2026-76460, a CVSS 10.0 unauthenticated API authentication-bypass vulnerability affecting Cisco Identity Services Engine, and CISA added it to the KEV Catalog. Cisco identified fixed releases including ISE 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, and stated that no workaround is available.
The Shadowserver Foundation identified more than 400 internet-exposed Cisco Secure Email Gateway appliances. The count was reported as of the preceding Monday.
CISA marked the actively exploited Cisco Secure Email Gateway vulnerability CVE-2026-76461 as requiring forensic triage under Binding Operational Directive 26-04, alongside its KEV listing and federal remediation requirement.
The Canadian Centre for Cyber Security issued advisory AV26-921 covering CVE-2026-76461 and urging administrators to review Cisco guidance and apply necessary updates.
CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities Catalog after active exploitation was reported.
Cisco disclosed that CVE-2026-76461 can be exploited without authentication by sending a crafted email with malicious SQL statements, potentially resulting in root-level operating-system command execution on affected Secure Email Gateway appliances. Cisco released AsyncOS 16.5.0-780 for customer-managed appliances, upgraded Secure Email Cloud devices, and stated that no workaround exists.
Cisco reported that CVE-2026-76461, an SQL injection vulnerability affecting Cisco Secure Email Gateway products, was being actively exploited.
Cisco released a security-hardening update for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.
A campaign exploiting the critical Cisco AsyncOS vulnerability CVE-2025-20393 reportedly operated from at least late November 2025. Cisco Talos assessed with moderate confidence that the China-linked UAT-9686 actor was responsible; reported tooling included AquaShell, AquaTunnel, Chisel, and AquaPurge.
Cisco's Product Security Incident Response Team became aware that attackers were actively exploiting CVE-2026-76461, an SQL injection flaw affecting Cisco Secure Email Gateway appliances.
KISA/KrCERT published an advisory recommending that affected organizations apply Cisco updates for CVE-2026-76460 in Cisco ISE and ISE-PIC, and CVE-2026-76461 in Cisco Secure Email Gateway. The advisory listed ISE and ISE-PIC patch levels for versions 3.1 through 3.5 and AsyncOS remediation releases for versions 15.5, 16.0, and 16.5.
Uganda National CERT and Coordination Center (CERT.UG/CC) advised administrators using affected Cisco Secure Email Gateway or Secure Email and Web Manager appliances to review Cisco guidance and apply the AsyncOS security updates for CVE-2026-76461.
Guyana National CIRT advised users and administrators to review Cisco's updates and apply them as necessary for the actively exploited Cisco Secure Email Gateway SQL injection flaw CVE-2026-76461.
Cisco released Snort rules 67109 and 67110 to help detect exploitation attempts targeting the actively exploited CVE-2026-76461 SQL injection vulnerability in Cisco Secure Email Gateway appliances.
Cisco issued a separate advisory for five additional vulnerabilities in Cisco Secure Email Gateway and Secure Email and Web Manager: four critical flaws (CVE-2026-76440, CVE-2026-76441, CVE-2026-76443, and CVE-2026-20353) and one high-severity flaw (CVE-2026-76442). Fixed Secure Email Gateway releases include 15.5.5-014 and 16.5.0-780, while Secure Email and Web Manager fixes include 15.5.5-006 and 16.5.0-429.
CISA ordered U.S. federal civilian agencies to remediate the actively exploited Cisco Secure Email Gateway vulnerability CVE-2026-76461. The directive set a remediation deadline of September 17, 2026.
Cisco released indicators of compromise for exploitation of CVE-2026-76461 and cautioned that attackers who obtain root-level access may remove or hide those indicators. The company also stated the flaw affects physical and virtual Secure Email Gateway appliances in all configurations.
Finland's National Cyber Security Centre advised organizations investigating Cisco Secure Email Gateway exploitation to inspect mail_logs for suspicious SQL statements, particularly patterns resembling `COPY.*TO PROGRAM`, and to review network logs for anomalous traffic.
Cisco reportedly identified AsyncOS 16.0.4-3021 and 15.5.5-0141 as remediated releases alongside 16.5.0-780. It also advised organizations investigating suspected compromise to review mail and network telemetry, preserve forensic evidence, rebuild suspect virtual instances, and rotate credentials and certificates.
Cisco conducted remediation and recovery work for Secure Email Cloud devices where it identified possible compromise indicators and directly contacted the affected customers. Cisco did not disclose the number or identities of potentially affected on-premises customers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
42 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourceboho.or.kr
Open sourcexakep.ru
Open sourcetruesec.com
Open sourcegithub.com
Open sourcecve.org
Open sourcecisa.gov
Open sourcedashboard.shadowserver.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.