Cisco releases security updates for a critical zero-day affecting its Secure Email Gateway, warning that the flaw is actively exploited by attackers. Cisco says it is aware of ongoing exploitation of the vulnerability and urges customers to apply available patches to affected appliances.

Help Net Security and Bleeping Computer both report that the weakness is being used in real-world attacks against Cisco Secure Email Gateway deployments. Help Net Security specifies the issue as a zero-day SQL injection vulnerability labeled CVE-2026-76461, with exploitation and response activity identified as beginning in September 2025. The vendor’s Product Security Incident Response Team provides indicators of compromise for organizations to check whether their systems may be affected.

Across the reporting, the shared focus is urgency: Cisco customers are instructed to remediate promptly and use IoCs for detection. The articles align on the fact that exploitation is occurring in the wild, while Help Net Security additionally details the affected software versions and the CVE identifier.