Security · September 17, 2026

Cisco Systems Releases Security Update for Secure Email Gateway Due to Active Exploitation

Computer code on a dark screen with line numbers
Harshit Katiyar / Unsplash

Cisco Systems has released a security update for Cisco Secure Email Gateway to address a vulnerability that is being exploited.

The issue is identified as CVE-2026-76461, which is a SQL injection vulnerability. It stems from insufficient input validation during email analysis processing. This flaw may allow an unauthenticated remote attacker to execute arbitrary SQL when the system processes a specially crafted email.

Through this attack, it is possible for an attacker to obtain root privileges for the underlying operating system and execute arbitrary commands. The vulnerability has a CVSSv3.1 base score of 9.8 and is rated as Critical, the highest of four levels. Cisco Systems confirmed that exploitation of CVE-2026-76461 occurred in September 2026.

To resolve this, the company provided updated versions including Cisco Secure Email Gateway 16.5.0-780, 16.0.4-3021, and 15.5.5-0141. Cisco Systems strongly recommends migrating to version 16.5.0-780, which also includes measures for multiple other vulnerabilities. Users of other branches must verify their specific versions as the target versions for fixes differ.