Cisco security advisory (AV26-921)

Used in attacksCriticalCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
Critical
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-76461
Vendors and products
Cisco
Industries
Government
Reported by
1 outlet

As of September 14, 2026, Cisco is affected by vulnerabilities in the following products:

  • Cisco AsyncOS for Cisco Secure Email Gateway
    • Prior to 15.5.5-014
    • Prior to 16.0.4-302
    • Prior to 16.5.0-780
  • Cisco Secure Email Gateway
    • Prior to 15.5.5-014
    • Prior to 16.5.0-780
  • Cisco Secure Email and Web Manager
    • Prior to 15.5.5-006
    • Prior to 16.5.0-429

On September 14, 2026, Cisco stated that CVE-2026-76461 is being actively exploited.

On September 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • CVE-2026-764619.8Critical

    Cisco Secure Email Gateway

    Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

    Used in attacks

    Added to CISA's list 2026-09-14 · Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-14 19:23 UTC

Related stories