CVE-2026-76461
As of September 14, 2026, Cisco is affected by vulnerabilities in the following products: Cisco AsyncOS for Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.0.4-302 Prior to 16.5.0-780 Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.5.0-780 Cisco Secure Email and Web Manager Prior to 15.5.5-006 Prior to 16.5.0-429 On September 14, 2026, Cisco stated that CVE-2026-76461 is being actively exploited. On September 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prior | Prior to 16.0.4-302 | |
| Prior | Prior to 15.5.5-014 | |
| Prior | Prior to 16.5.0-780 | |
| Prior | Prior to 16.5.0-429 | |
| Prior | Prior to 15.5.5-006 |
Timeline
- Sep 14, 2026 CISA KEV Added
- Sep 14, 2026 VulnCheck KEV Exploitation
- Sep 14, 2026 Coalition ESS Score
- Sep 14, 2026 CVE Published
References
- https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-921 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX vendor
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm vendor
- https://sec.cloudapps.cisco.com/security/center/publicationListing.x vendor
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461 advisory