Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cisco's two exploited flaws and CISA's patch clock

The main case On Monday, September 14, a researcher publishes the details of CVE-2026-76461 ( Source: SOCRadar ), a remote code execution with root privileges in Cisco Secure Email Gateway. The vector is an email with malicious SQL inside it. No authentication required, no user interaction required, nothing required except the message reaching the gateway (helpnetsecurity.com). That same day,…

On Monday, September 14th, a researcher disclosed details of two critical vulnerabilities in Cisco's Secure Email Gateway and Identity Services Engine. The first, CVE-2026-76461, allowed remote code execution with root privileges via a malicious SQL injection in an email. The second, CVE-2026-76460, enabled authentication bypass without requiring any credentials.

Both were added to the Known Exploited Vulnerabilities catalog by the Cybersecurity and Infrastructure Security Agency (CISA) and had deadlines for patching set to September 17th and 19th respectively. This means that U.S. federal agencies had only three days to address these severe flaws.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Friday 18 September →