Cisco has patched CVE-2026-76461, an actively exploited Secure Email Gateway SQL injection flaw that can let unauthenticated attackers run commands as root. Because CISA added it to the KEV catalog with a September 17 deadline, admins should treat patching as the start of incident triage, not the end.
Attackers are actively exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin, a flaw that can expose mail-service API keys, OAuth tokens, plugin versions, and server details. Site owners should update to Gravity SMTP 2.1.5 or later, check logs, and rotate affected email credentials.