Cisco's two exploited flaws and CISA's patch clock
CISA added two Cisco vulnerabilities to the KEV catalog: CVE-2026-76461 in Secure Email Gateway (RCE with root via SQL injection in email) and CVE-2026-76460 in ISE (authentication bypass, CVSS 10.0). US federal agencies have deadlines of September 17 and 19 respectively.
- CVE-2026-76461: RCE with root in Cisco Secure Email Gateway without authentication
- CVE-2026-76460: authentication bypass in Cisco ISE with CVSS 10.0
- CISA set patch deadlines for federal agencies: September 17 and 19
- Both vulnerabilities already exploited in real attacks
Read next
Security