Advisories
Cisco Hardens Secure Email Gateway with Critical Patch for Exploited SQL Injection
Cisco rolled out a hardening update for its Secure Email Gateway and Secure Email & Web Manager after an internal audit uncovered several critical flaws, including a live SQL injection exploit. The fix bundles five CVEs (CVE‑2026‑20353, 76440‑76443) into a single patch with no workarounds, demanding immediate action from customers to maintain email security.
Cisco’s engineering teams just released a hardening update for its Secure Email Gateway and Secure Email & Web Manager. The update comes after an internal security review exposed multiple critical weaknesses, one of which is actively being exploited in the wild.
Key Points
- Five CVEs (CVE‑2026‑20353, 76440‑76441, 76442, 76443) tied to a single underlying CWE class.
- One flaw is a live SQL injection that attackers are already using.
- No workarounds are available; a patch is the only fix.
- Security impact rated as Critical.
"This hardening release is a direct response to vulnerabilities found during internal testing, underscoring Cisco’s proactive stance on product security," says the advisory.
Customers must download and apply the latest firmware/patches immediately to close these gaps. Failure to do so could expose email traffic to injection attacks and other exploitation vectors.