Cisco security advisory (AV26-921)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-921 Date: September 14, 2026 As of September 14, 2026, Cisco is affected by vulnerabilities in the following products: Cisco AsyncOS for Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.0.4-302 Prior to 16.5.0-780 Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.5.0-780 Cisco Secure Email and Web Manager Prior to 15.5.5-006 Prior to 16.5.0-429 On September 14, 2026, Cisco stated that CVE-2026-76461 is being actively exploited. On September 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Cisco Secure Email Gateway SQL Injection Vulnerability Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 Cisco Security Advisories CISA KEV: CVE-2026-76461
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-921
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-76461Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-76461 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[NEU] [hoch] Cisco Secure Email Gateway: Mehrere Schwachstellencert-bund
- unknownexploitedCisco Products Multiple Vulnerabilitieshkcert
- unknownexploitedMultiples vulnérabilités dans les produits Cisco (15 septembre 2026)cert-fr-avis
- unknownexploitedNCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email Gatewayncsc-nl
- criticalexploitedCVE-2026-76461: A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway …nvd
- criticalexploitedCisco Secure Email Gateway SQL Injection Vulnerabilitycisco-psirt
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerabilitycisa-kev
More from Canadian Centre for Cyber Security
- unknownAndroid security advisory – September 2026 monthly rollup (AV26-920)2026-09-14
- unknownSamsung mobile security advisory (AV26-919)2026-09-14
- unknownMongoDB security advisory (AV26-918)2026-09-14
- criticalGitLab security advisory (AV26-917)2026-09-11
- unknownJFrog security advisory (AV26-867) – Update 22026-09-11