All posts

Cisco Secure Email Gateway Zero-Day CVE-2026-76461 Hits KEV

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 16, 2026

Cisco Secure Email Gateway zero-day CVE-2026-76461 is being exploited

Cisco has patched an actively exploited zero-day in Secure Email Gateway, tracked as CVE-2026-76461, a SQL injection flaw carrying a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-14. This is the day's most consequential item because it is confirmed exploited in attacks and, per BleepingComputer, allows an attacker to execute commands as root on the appliance.

Rapid7 and Help Net Security both report exploitation in the wild. An email gateway sits in front of your mail flow and holds credentials and routing to your tenant, so a root-level compromise there is not something to schedule for the next maintenance window. If you run Secure Email Gateway, treat this as patch now, not patch eventually.

KEV additions and the ransomware movers

The exploitation picture around it is crowded. Cisco Firewall Management Center CVE-2026-20079, an authentication bypass with a maximum CVSS of 10 and EPSS near 0.76, is on KEV and topping the hot list. GitLab CVE-2026-85706, the maximum severity path traversal that Dark Reading flagged as a supply chain risk, remains KEV listed.

Three KEV entries are now tied to ransomware and deserve priority. SonicWall SMA1000 SSRF CVE-2026-15409 (CVSS 10) and WebPros cPanel and WHM CVE-2026-41940 (CVSS 9.8, EPSS 0.9853) are both ransomware-linked. Broadcom VMware vCenter path traversal CVE-2026-59310 (CVSS 9.8) is the one BleepingComputer confirms is now exploited by ransomware gangs. If you run vCenter, that changes its priority: it is KEV, it is ransomware, patch it.

What the press adds on Microsoft patches

Dark Reading reports Microsoft issued emergency fixes following a massive Patch Tuesday. Two known issues are worth tracking before you deploy broadly. BleepingComputer confirms the September KB5002914 Excel update breaks copy and paste, and Qualys is making the case for patch reliability testing around this cycle, referencing KB5124008 and KB5124012.

Several Windows 10 1809 cumulative updates in the hot list, including KB5124008, carry hundreds of CVEs and KEV-listed fixes. Test the Excel regression against your workflows, but do not let a copy-and-paste bug stall the security content.

Do this first

Grounded in today's facts, here is the order that makes sense.

  • Patch Cisco Secure Email Gateway for CVE-2026-76461 immediately; it is KEV listed and exploited to run commands as root.
  • Prioritize the ransomware-linked KEV entries next: VMware vCenter CVE-2026-59310, SonicWall SMA1000 CVE-2026-15409, and WebPros cPanel CVE-2026-41940.
  • Confirm Cisco FMC CVE-2026-20079 and GitLab CVE-2026-85706 are remediated in your estate.
  • Stage this month's Windows updates, including KB5124008, and validate the KB5002914 Excel copy-and-paste issue before wide rollout.

Check your own patch state

After a KEV add, the useful question is whether you are actually exposed. Senserva's free non-Microsoft exploited-CVE tracker follows CISA KEV additions daily, so items like CVE-2026-76461 and the vCenter flaw surface as they land. The free Microsoft Patch Tracker ranks open Microsoft patches by KEV, EPSS, and ransomware linkage, which helps you sequence this month's cumulative updates against the noise.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-16.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.