Browsing Tag
Cisco PSIRT
2 posts
Cisco Product Security Incident Response Team advisories, vulnerability disclosure, and remediation guidance.
Cisco Email Gateway Zero-Day Turns Mail Security Into Incident Triage
Cisco has patched CVE-2026-76461, an actively exploited Secure Email Gateway SQL injection flaw that can let unauthenticated attackers run commands as root. Because CISA added it to the KEV catalog with a September 17 deadline, admins should treat patching as the start of incident triage, not the end.
Cisco’s Twice-Monthly Patch Cadence Starts With Catalyst Center and ClamAV Fixes
Cisco’s first July security-advisory drop under its new twice-monthly cadence includes a Catalyst Center arbitrary-file-read flaw and seven ClamAV vulnerabilities affecting Cisco Secure Endpoint. The change gives network and security teams more predictability, but it also means Cisco infrastructure patch planning needs to become a standing operating rhythm, not a quarterly scramble.