CISA and Cisco encourage affected organizations to apply vendor patches for Cisco Secure Email Gateway as soon as possible. Federal agencies must follow the remediation timelines and requirements specified in Binding Operational Directive (BOD) 26-04. Organizations should also check whether threat actors may have already compromised systems before applying patches, and document any pre-compromise indicators. All organizations are advised to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
Quick answers
What is CVE-2026-76461?
CISA and Cisco encourage affected organizations to apply vendor patches for Cisco Secure Email Gateway as soon as possible. Federal agencies must follow the remediation timelines and requirements specified in Binding Operational Directive (BOD) 26-04. Organizations should also check whether threat actors may have already compromised systems before applying patches, and document any pre-compromise indicators. All organizations are advised to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
How severe is CVE-2026-76461?
high
Is CVE-2026-76461 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-76461 be mitigated?
CISA and Cisco encourage affected organizations to apply vendor patches for Cisco Secure Email Gateway as soon as possible. Federal agencies must follow the remediation timelines and requirements specified in Binding Operational Directive (BOD) 26-04. Organizations should also check whether threat actors may have already compromised systems before applying patches, and document any pre-compromise indicators. All organizations are advised to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
CVSS
—
Vendor
Cisco
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Cisco Secure Email Gateway
Mitigation
CISA and Cisco encourage affected organizations to apply vendor patches for Cisco Secure Email Gateway as soon as possible. Federal agencies must follow the remediation timelines and requirements specified in Binding Operational Directive (BOD) 26-04. Organizations should also check whether threat actors may have already compromised systems before applying patches, and document any pre-compromise indicators. All organizations are advised to adopt risk-based vulnerability management practices and prioritize remediation of KEV Catalog vulnerabilities on publicly exposed assets.
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition is based on evidence of active exploitation. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of this vulnerability on publicly exposed assets that could grant total system control post-exploitation. CISA encourages all organizations to adopt similar risk-based prioritization.