Junglewise Threat Intelligence

CVE-2026-76440: Cisco Secure Email Gateway path traversal

CVE-2026-76440 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Technologies: Cisco Secure Email Gateway, Cisco Secure Email and Web Manager. Vendors: Cisco.

Executive brief

Cisco Secure Email Gateway and Secure Email and Web Manager are email security appliances used to filter and protect enterprise email. Multiple path traversal and related vulnerabilities in these products could allow unauthenticated attackers to bypass security controls and access sensitive files or systems without proper authorization, potentially compromising email security and customer data.

Technical details

CVE-2026-76440 is a path traversal vulnerability (CWE-23) affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The vulnerability allows improper limitation of pathnames to restricted directories and improper link resolution before file access. The advisory groups multiple internally discovered vulnerabilities by CWE category; CVE-2026-76440 specifically represents path traversal issues with a CVSS 9.8 score indicating network-reachable, unauthenticated remote code execution or arbitrary file access potential. Attack vector is network-based with no authentication or user interaction required. Cisco has released fixed software versions: Secure Email Gateway 15.5.5-014 and 16.5.0-780; Secure Email and Web Manager 15.5.5-006 and 16.5.0-429. No workarounds are available.

Affected products

  • Cisco Secure Email Gateway 15.5 and earlier; 16.0; 16.5 (fixed in 15.5.5-014, 16.5.0-780)
  • Cisco Secure Email and Web Manager 15.5 and earlier; 16.0; 16.5 (fixed in 15.5.5-006, 16.5.0-429)

Timeline

  • 2026-09-14: disclosed

References

Related threats