Advisory: Active Exploitation of CVE-2026-76461 in Cisco Email Security Products
As of September 14, 2026, Cisco has confirmed that several of its email security products are vulnerable to CVE-2026-76461, which is currently being actively exploited. This vulnerability affects the following products:
- Cisco AsyncOS for Cisco Secure Email Gateway
- Versions prior to 15.5.5-014
- Versions prior to 16.0.4-302
- Versions prior to 16.5.0-780
- Cisco Secure Email Gateway
- Versions prior to 15.5.5-014
- Versions prior to 16.5.0-780
- Cisco Secure Email and Web Manager
- Versions prior to 15.5.5-006
- Versions prior to 16.5.0-429
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76461 to its Known Exploited Vulnerabilities (KEV) Database, highlighting the urgency of addressing this issue. Organizations using the affected Cisco products should prioritize reviewing their systems and applying any necessary updates as soon as they become available.
For further details and guidance, users and administrators are encouraged to consult the official advisory from the Cyber Centre.
Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.



