Cisco security advisory (AV26-921)

Serial Number: AV26-921
Date: September 14, 2026

As of September 14, 2026, Cisco is affected by vulnerabilities in the following products:

  • Cisco AsyncOS for Cisco Secure Email Gateway
    • Prior to 15.5.5-014
    • Prior to 16.0.4-302
    • Prior to 16.5.0-780
  • Cisco Secure Email Gateway
    • Prior to 15.5.5-014
    • Prior to 16.5.0-780
  • Cisco Secure Email and Web Manager
    • Prior to 15.5.5-006
    • Prior to 16.5.0-429

On September 14, 2026, Cisco stated that CVE-2026-76461 is being actively exploited.

On September 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Date modified: