Our takeCISA added CVE-2026-76461 (Cisco Secure Email Gateway SQLi) to its KEV catalog: confirmed exploited in the wild. Patch it now.Cyber Resilience desk
Sources (2)
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA added CVE-2026-76461 (Cisco Secure Email Gateway SQL injection) to its KEV catalog: confirmed exploited in the wild. Federal agencies must mitigate by the BOD 26-04 deadline; all others should prioritize patching or apply mitigations now.
What this means for you — Lean IT orgs:CISA added a Cisco Secure Email Gateway SQL injection flaw to its KEV list: it is confirmed exploited in the wild. Check if you run the on-prem gateway and patch or disable it immediately if you do.
What this means for you — MSP:CISA added CVE-2026-76461 (Cisco Secure Email Gateway SQL injection) to its KEV catalog: confirmed exploited in the wild. Review all client environments running on-prem Secure Email Gateway and patch or apply workarounds promptly.
What this means for you — Researcher:CISA added one new entry to its KEV catalog: CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway confirmed exploited in the wild.