VORANT. Threat Intelligence Sign in Get the full feed

Cisco Secure Email Gateway flaw exploited in wild

high vulnerability technology

ANSSI warns of multiple Cisco Secure Email/Web Manager and AsyncOS vulnerabilities, including CVE-2026-76461 which is actively exploited.

ANSSI (CERT-FR) has issued an advisory relaying two Cisco security bulletins covering multiple vulnerabilities affecting AsyncOS for Secure Email Gateway, Secure Email and Web Manager, and Secure Email Gateway products. The flaws span several impact categories: remote arbitrary code execution, remote denial of service, SQL injection, indirect code injection (XSS), and security policy bypass. Cisco has confirmed that CVE-2026-76461 is being actively exploited in the wild, making patching urgent for affected deployments.

Affected versions include AsyncOS for Secure Email Gateway 16.0.x before 16.0.4-3021, 16.5.x before 16.5.0-780, and versions before 15.5.5-0141; Secure Email and Web Manager 16.x before 16.5.0-429 and versions before 15.5.5-006; and Secure Email Gateway 16.x before 16.5.0-780 and versions before 15.5.5-014. Six CVEs are referenced (CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, CVE-2026-76443, CVE-2026-76461), tied to two Cisco advisories (cisco-sa-esa-inj-2bLVGmhX and cisco-sa-hardening-esa-dfCrfXkm) published 14 September 2026. Defenders operating Cisco email security gateways should prioritize patching to the fixed versions immediately, with particular urgency for the actively exploited CVE-2026-76461, and consult the Cisco advisories for detection guidance and applicable indicators.

No specific IOCs, threat actor attribution, or exploitation TTP details were provided in this advisory beyond confirmation of active exploitation; organizations should monitor Cisco's advisory pages for updates and apply vendor patches as the primary mitigation.

Mentioned in this report

Vulnerabilities CVE-2026-20353CVE-2026-76440CVE-2026-76441CVE-2026-76442CVE-2026-76443CVE-2026-76461KEV

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1175

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free