Executive brief
Cisco Secure Email Gateway and Secure Email and Web Manager are critical infrastructure appliances used to filter and manage email traffic for enterprises. Multiple improper access control vulnerabilities allow unauthenticated remote attackers to bypass authentication and authorization controls, potentially gaining full administrative access and compromising all email communications and data passing through these systems.
Technical details
CVE-2026-76441 covers improper access control vulnerabilities (CWE-284) grouped with other hardening issues including path traversal (CWE-23), improper resource control (CWE-664), and injection flaws (CWE-707). The vulnerabilities are network-reachable and require no authentication or user interaction, with a CVSS base score of 9.8 indicating potential for complete system compromise. Cisco has released patched versions (ESA 15.5.5-014 and 16.5.0-780; EWMA 15.5.5-006 and 16.5.0-429) following an internal security review that discovered these issues during testing. One related SQL injection vulnerability in this advisory is known to be actively exploited in the wild.
Affected products
- Cisco Secure Email Gateway 15.5 and earlier; 16.0; 16.5 before 16.5.0-780
- Cisco Secure Email and Web Manager 15.5 and earlier; 16.0; 16.5 before 16.5.0-429
Timeline
- 2026-09-14: disclosed: Cisco Security Advisory published
- 2026-09-14: patched: Fixed versions released: ESA 15.5.5-014, 16.5.0-780; EWMA 15.5.5-006, 16.5.0-429
- exploited: Related SQL injection vulnerability (CVE-2026-76443) in this advisory group known to be actively exploited