← Back

Wire · opportunities

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Published

15 September 2026

Topic

opportunities

Sectors

Cybersecurity

Geography

United States

Source

Read at helpnetsecurity.com

Verified

Fusion42 · 15 September 2026 · Fusion42 review

Cisco patched a zero-day SQL injection vulnerability (CVE-2026-76461) actively exploited in its Secure Email Gateway appliances, affecting both on-premises and cloud versions. US CISA ordered federal agencies to remediate by September 17, highlighting the critical risk of root-level compromise via crafted emails without user interaction.

This Wire brief sits within Fusion42's coverage of Cybersecurity, and 3 sources have reported it.

◆ The Wire takeaway

You must act fast to update any Cisco Secure Email Gateway appliances or cloud services to avoid root-level breaches that can erase evidence. Security teams have a tight remediation deadline from US government authorities that makes this a immediate compliance and risk priority.

Coverage

3 sources · 15 Sep 2026

Related on Wire

Topics

Cybersecurityciscoemail-securityzero-daysql-injectionus-cisapatch