CISA Adds One Known Exploited Vulnerability to Catalog
Summary
CISA has added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition aligns with Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize remediation of high-risk vulnerabilities listed in the KEV Catalog.
IFF Assessment
The addition of a newly exploited vulnerability to CISA's KEV catalog indicates a real-world threat that defenders must address, posing a risk to their systems.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 17, 2026. Known ransomware use: Unknown.
Defender Context
Organizations, especially federal agencies, need to promptly patch CVE-2026-76461 as it has been confirmed as actively exploited. This highlights the ongoing importance of CISA's KEV catalog for risk-based vulnerability management and prioritizing remediation efforts.