# Cisco Secure Email Gateway flaw exploited in wild

Published: 2026-09-15 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/04fd68be-9d3c-5c66-8231-e9dd6fece334/cisco-secure-email-gateway-flaw-exploited-in-wild

> ANSSI warns of multiple Cisco Secure Email/Web Manager and AsyncOS vulnerabilities, including CVE-2026-76461 which is actively exploited.

ANSSI (CERT-FR) has issued an advisory relaying two Cisco security bulletins covering multiple vulnerabilities affecting AsyncOS for Secure Email Gateway, Secure Email and Web Manager, and Secure Email Gateway products. The flaws span several impact categories: remote arbitrary code execution, remote denial of service, SQL injection, indirect code injection (XSS), and security policy bypass. Cisco has confirmed that CVE-2026-76461 is being actively exploited in the wild, making patching urgent for affected deployments.

Affected versions include AsyncOS for Secure Email Gateway 16.0.x before 16.0.4-3021, 16.5.x before 16.5.0-780, and versions before 15.5.5-0141; Secure Email and Web Manager 16.x before 16.5.0-429 and versions before 15.5.5-006; and Secure Email Gateway 16.x before 16.5.0-780 and versions before 15.5.5-014. Six CVEs are referenced (CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, CVE-2026-76443, CVE-2026-76461), tied to two Cisco advisories (cisco-sa-esa-inj-2bLVGmhX and cisco-sa-hardening-esa-dfCrfXkm) published 14 September 2026. Defenders operating Cisco email security gateways should prioritize patching to the fixed versions immediately, with particular urgency for the actively exploited CVE-2026-76461, and consult the Cisco advisories for detection guidance and applicable indicators.

No specific IOCs, threat actor attribution, or exploitation TTP details were provided in this advisory beyond confirmation of active exploitation; organizations should monitor Cisco's advisory pages for updates and apply vendor patches as the primary mitigation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, CVE-2026-76443, CVE-2026-76461 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1175

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/04fd68be-9d3c-5c66-8231-e9dd6fece334/cisco-secure-email-gateway-flaw-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
