Cisco Secure Email Gateway zero-day CVE-2026-76461 is being exploited
Cisco has patched an actively exploited zero-day in Secure Email Gateway, tracked as CVE-2026-76461, a SQL injection flaw carrying a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-14. This is the day's most consequential item because it is confirmed exploited in attacks and, per BleepingComputer, allows an attacker to execute commands as root on the appliance.
Rapid7 and Help Net Security both report exploitation in the wild. An email gateway sits in front of your mail flow and holds credentials and routing to your tenant, so a root-level compromise there is not something to schedule for the next maintenance window. If you run Secure Email Gateway, treat this as patch now, not patch eventually.
KEV additions and the ransomware movers
The exploitation picture around it is crowded. Cisco Firewall Management Center CVE-2026-20079, an authentication bypass with a maximum CVSS of 10 and EPSS near 0.76, is on KEV and topping the hot list. GitLab CVE-2026-85706, the maximum severity path traversal that Dark Reading flagged as a supply chain risk, remains KEV listed.
Three KEV entries are now tied to ransomware and deserve priority. SonicWall SMA1000 SSRF CVE-2026-15409 (CVSS 10) and WebPros cPanel and WHM CVE-2026-41940 (CVSS 9.8, EPSS 0.9853) are both ransomware-linked. Broadcom VMware vCenter path traversal CVE-2026-59310 (CVSS 9.8) is the one BleepingComputer confirms is now exploited by ransomware gangs. If you run vCenter, that changes its priority: it is KEV, it is ransomware, patch it.
What the press adds on Microsoft patches
Dark Reading reports Microsoft issued emergency fixes following a massive Patch Tuesday. Two known issues are worth tracking before you deploy broadly. BleepingComputer confirms the September KB5002914 Excel update breaks copy and paste, and Qualys is making the case for patch reliability testing around this cycle, referencing KB5124008 and KB5124012.
Several Windows 10 1809 cumulative updates in the hot list, including KB5124008, carry hundreds of CVEs and KEV-listed fixes. Test the Excel regression against your workflows, but do not let a copy-and-paste bug stall the security content.
Do this first
Grounded in today's facts, here is the order that makes sense.
- Patch Cisco Secure Email Gateway for CVE-2026-76461 immediately; it is KEV listed and exploited to run commands as root.
- Prioritize the ransomware-linked KEV entries next: VMware vCenter CVE-2026-59310, SonicWall SMA1000 CVE-2026-15409, and WebPros cPanel CVE-2026-41940.
- Confirm Cisco FMC CVE-2026-20079 and GitLab CVE-2026-85706 are remediated in your estate.
- Stage this month's Windows updates, including KB5124008, and validate the KB5002914 Excel copy-and-paste issue before wide rollout.
Check your own patch state
After a KEV add, the useful question is whether you are actually exposed. Senserva's free non-Microsoft exploited-CVE tracker follows CISA KEV additions daily, so items like CVE-2026-76461 and the vCenter flaw surface as they land. The free Microsoft Patch Tracker ranks open Microsoft patches by KEV, EPSS, and ransomware linkage, which helps you sequence this month's cumulative updates against the noise.
Sources
- Help Net Security: Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) (2026-09-15)
- BleepingComputer: Cisco patches Secure Email Gateway zero-day exploited in attacks (2026-09-15)
- Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild (2026-09-15)
- BleepingComputer: CISA: Critical VMware RCE flaw now exploited by ransomware gangs (2026-09-15)
- Dark Reading: Maximum Severity GitLab Flaw Puts Supply Chains at Risk (2026-09-14)
- Dark Reading: Microsoft Issues Emergency Fixes After Massive Patch Tuesday (2026-09-15)
- BleepingComputer: Microsoft confirms KB5002914 Excel update breaks copy and paste (2026-09-15)
- Qualys: Before You Patch. Why Patch Reliability Matters for Confident Deployment (2026-09-15)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-16.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.