Actively Exploited Cisco Secure Email Gateway Flaw Added to CISA's Watchlist
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2026-76461, to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw affects Cisco Secure Email Gateway and is a SQL injection vulnerability, meaning attackers can manipulate database queries to gain unauthorised access or control over affected systems.
While CISA's binding directive requiring rapid patching applies only to US federal agencies, the agency strongly encourages all organisations, including Australian small and medium businesses, to prioritise fixing vulnerabilities listed in the KEV Catalog. These vulnerabilities are included because there is confirmed evidence they are being actively exploited by attackers, making them higher priority than general software bugs.
Email security gateways sit at the front line of business communications and are attractive targets because compromising them can expose sensitive email traffic or provide a foothold into wider networks. Businesses using Cisco Secure Email Gateway should check for available patches and apply them without delay.