Cisco disclosed active exploitation of CVE-2026-76461, an SQL injection flaw affecting Cisco Secure Email Gateway deployments. The vulnerability affects unpatched releases of Cisco AsyncOS for Cisco Secure Email Gateway, Cisco Secure Email Gateway, and Cisco Secure Email and Web Manager.
CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities Catalog, while the Canadian Centre for Cyber Security issued advisory AV26-921. Cisco has released a September 2026 security-hardening update; administrators should identify affected appliances and management systems and apply Cisco’s prescribed fixed releases promptly.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-921 covering CVE-2026-76461 and urging administrators to review Cisco guidance and apply necessary updates.
CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities Catalog after active exploitation was reported.
Cisco disclosed that CVE-2026-76461 can be exploited without authentication by sending a crafted email with malicious SQL statements, potentially resulting in root-level operating-system command execution on affected Secure Email Gateway appliances. Cisco released AsyncOS 16.5.0-780 for customer-managed appliances, upgraded Secure Email Cloud devices, and stated that no workaround exists.
Cisco reported that CVE-2026-76461, an SQL injection vulnerability affecting Cisco Secure Email Gateway products, was being actively exploited.
Cisco released a security-hardening update for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcelabs.beazley.security
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.