
・CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX 『(直訳)Cisco Secure Email Gateway 用の Cisco AsyncOS ソフトウェアのメール解析機能に脆弱性があり、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でルート権限で任意のコマンドを実行できる可能性』 →KEV追加 ・CVE-2026-20353/CVE-2026-76440/CVE-2026-76441/CVE-2026-76442/CVE-2026-76443 Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm 『(直訳)これらの脆弱性は、社内テスト中に発見されました。そのうちの1つは、実際に悪用されていることが確認されています。』




