Cisco Patches Actively Exploited Zero-Day Vulnerability (CVE-2026-76461) in Secure Email Gateway

AI-generated NewsSnap summary based on source reporting.
Published: 2026-09-15
Category: technology
Source: Help Net Security

Cisco has released patches for a critical SQL injection zero-day vulnerability (CVE-2026-76461) affecting its Secure Email Gateway appliances, which is being actively exploited by attackers. The flaw, due to insufficient validation in email parsing logic, allows unauthenticated attackers to execute malicious SQL statements by sending a crafted email. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating remediation for U.S. federal civilian agencies.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai