CISA has added one vulnerability to its Known Exploited Vulnerabilities Catalog on the basis of evidence of active exploitation: CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway. The alert is deliberately terse and does not name an exploitation campaign, victim set or threat actor, which is the normal shape of a KEV addition that follows vendor confirmation rather than leading it. The compliance context is the operative part for defenders: Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritise remediation of KEV-listed flaws on publicly exposed assets that would grant total control post-exploitation, and to check whether systems were compromised before the patch was applied, while deferring action on lower-risk issues. CISA states the directive applies only to FCEB agencies but encourages all organisations to adopt the same risk-based prioritisation of KEV entries. The addition lands after an unusually heavy batch: seven flaws across JFrog Artifactory, ConnectWise ScreenConnect, MikroTik RouterOS, GitLab, Citrix NetScaler, Fortinet and Google Chromium were added between 09 and 11 September, which this digest covered on 13 September as the freshest exploited-in-the-wild signal on desks. A single add the following business day is a slowdown in catalog growth, not a slowdown in exploitation, and the correct reading for enterprise defenders is that secure email gateways โ frequently deployed on-premises, frequently internet-facing at the perimeter, and holding mail flow for the whole organisation โ belong on the same patching cadence as remote-access appliances.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-15 |
| Source | CISA |
| Reliability | Tier 1 |
| CVEs | CVE-2026-76461 |