Cisco Releases Critical Patches for Exploited SQL Injection Flaw in Secure Email Gateway
Cisco Systems has published security updates for Cisco Secure Email Gateway addressing a critical vulnerability that is already being exploited in the wild.
The flaw, identified as CVE-2026-76461, is an SQL injection issue caused by insufficient input validation in the email parsing process. Attackers can send specially crafted emails that trigger unauthenticated remote execution of arbitrary SQL commands.
According to Cisco, successful exploitation grants attackers root privileges on the underlying operating system, allowing them to run any commands on the affected appliance. The vulnerability received a CVSSv3.1 base score of 9.8 and is rated Critical.
Cisco confirmed exploitation of CVE-2026-76461 in September 2026. The company strongly recommends immediate migration to the fixed releases Cisco Secure Email Gateway 16.5.0-780, 16.0.4-3021, or 15.5.5-0141, with 16.5.0-780 being the preferred target. The 16.5.0-780 branch also contains additional fixes beyond this CVE.
Administrators are advised to review the release notes for their specific branch, as the exact fixed versions differ across maintenance streams.
Related articles
Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes
Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.
Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution
GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.
WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM
WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.
Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings
Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.