Cisco Product Security Update Advisory (CVE-2026-76461)

Cisco Product Security Update Advisory (CVE-2026-76461)

Overview


Cisco has released a security update to address a vulnerability in Cisco products. This advisory addresses CVE-2026-76461, which affects the Cisco Secure Email Gateway.

Affected Products


  • Cisco Secure Email Gateway versions earlier than 15.5.5-014.
  • Cisco Secure Email Gateway versions earlier than 16.0.4-302.
  • Cisco Secure Email Gateway versions earlier than 16.5.0-780.

Vulnerability Details


  • CVE-2026-76461 is an SQL injection vulnerability (a vulnerability that allows an attacker to exploit database queries through input manipulation) in the Cisco Secure Email Gateway.

Recommended Actions


  • Cisco has provided a Vulnerability Patch for this vulnerability in its latest update.
  • Users of the affected products should update to the latest version with the Vulnerability Patch following the instructions on the reference site.

References


  • Cisco Secure Email Gateway SQL Injection Vulnerability.
  • Https://sec.Cloudapps.Cisco.Com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX.