{
  "id": 8220425,
  "title": "Cisco's two exploited flaws and CISA's patch clock",
  "url": "https://urgent.news/2026/09/18/ciscos-two-exploited-flaws-and-cisas-patch-clock",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-18T09:19:02.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/analista_83/ciscos-two-exploited-flaws-and-cisas-patch-clock-4m12"
  },
  "original_language": "en",
  "account": "On Monday, September 14th, a researcher disclosed details of two critical vulnerabilities in Cisco's Secure Email Gateway and Identity Services Engine. The first, CVE-2026-76461, allowed remote code execution with root privileges via a malicious SQL injection in an email. The second, CVE-2026-76460, enabled authentication bypass without requiring any credentials. Both were added to the Known Exploited Vulnerabilities catalog by the Cybersecurity and Infrastructure Security Agency (CISA) and had deadlines for patching set to September 17th and 19th respectively. This means that U.S. federal agencies had only three days to address these severe flaws.",
  "summary": "The main case On Monday, September 14, a researcher publishes the details of CVE-2026-76461 ( Source: SOCRadar ), a remote code execution with root privileges in Cisco Secure Email Gateway. The vector is an email with malicious SQL inside it. No authentication required, no user interaction required, nothing required except the message reaching the gateway (helpnetsecurity.com). That same day,…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}