rootpwn

Advisories

Cisco Hardens Secure Email Gateway with Critical Patch for Exploited SQL Injection

Cisco rolled out a hardening update for its Secure Email Gateway and Secure Email & Web Manager after an internal audit uncovered several critical flaws, including a live SQL injection exploit. The fix bundles five CVEs (CVE‑2026‑20353, 76440‑76443) into a single patch with no workarounds, demanding immediate action from customers to maintain email security.

Cisco’s engineering teams just released a hardening update for its Secure Email Gateway and Secure Email & Web Manager. The update comes after an internal security review exposed multiple critical weaknesses, one of which is actively being exploited in the wild.

Key Points

  • Five CVEs (CVE‑2026‑20353, 76440‑76441, 76442, 76443) tied to a single underlying CWE class.
  • One flaw is a live SQL injection that attackers are already using.
  • No workarounds are available; a patch is the only fix.
  • Security impact rated as Critical.
"This hardening release is a direct response to vulnerabilities found during internal testing, underscoring Cisco’s proactive stance on product security," says the advisory.

Customers must download and apply the latest firmware/patches immediately to close these gaps. Failure to do so could expose email traffic to injection attacks and other exploitation vectors.

Cisco Secure Email Gateway Vulnerabilities Hardening CVE Critical SQL Injection

← All news