Security · September 17, 2026
Also published in Norsk, Deutsch, Español, Italiano, Nederlands, Svenska, Português (Brasil), Polski
Cisco Systems Releases Security Update for Secure Email Gateway Due to Active Exploitation
Cisco Systems has released a security update for Cisco Secure Email Gateway to address a vulnerability that is being exploited.
The issue is identified as CVE-2026-76461, which is a SQL injection vulnerability. It stems from insufficient input validation during email analysis processing. This flaw may allow an unauthenticated remote attacker to execute arbitrary SQL when the system processes a specially crafted email.
Through this attack, it is possible for an attacker to obtain root privileges for the underlying operating system and execute arbitrary commands. The vulnerability has a CVSSv3.1 base score of 9.8 and is rated as Critical, the highest of four levels. Cisco Systems confirmed that exploitation of CVE-2026-76461 occurred in September 2026.
To resolve this, the company provided updated versions including Cisco Secure Email Gateway 16.5.0-780, 16.0.4-3021, and 15.5.5-0141. Cisco Systems strongly recommends migrating to version 16.5.0-780, which also includes measures for multiple other vulnerabilities. Users of other branches must verify their specific versions as the target versions for fixes differ.