September 16, 2026
- CVE-2026-76461 in Cisco Secure Email Gateway is being exploited for unauthenticated, root-level command execution. The AsyncOS email-parsing flaw is described by CERT-SE as SQL injection, and CISA has added it to KEV. Cisco recommends upgrading to 16.5.0-780; CERT-SE urges immediate remediation and compromise review (Cisco advisory; CERT-SE). · Vulnerabilities & Exploitation
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways