Junglewise Threat Intelligence

CVE-2026-76442: Cisco Secure Email Gateway improper input validation

CVE-2026-76442 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Cisco Secure Email and Web Manager, Cisco Secure Email Gateway. Vendors: Cisco.

Executive brief

Cisco Secure Email Gateway and Secure Email and Web Manager are email security appliances used to filter threats and manage message flow in enterprise environments. This vulnerability involves improper validation of quantity fields in input, which could allow attackers to trigger excessive resource consumption and degrade service availability.

Technical details

The vulnerability (CVE-2026-76442) is classified under CWE-1284 (improper validation of specified quantity in input) and involves unbounded numeric fields that drive excessive resource consumption. It affects Cisco Secure Email Gateway and Cisco Secure Email and Web Manager regardless of device configuration. The issue is remotely exploitable over the network with no authentication or user interaction required. Attackers can craft malicious input with excessive numeric quantities to exhaust system resources and cause denial of service. Cisco has released fixed software versions: ESA 15.5.5-014, 16.5.0-780 and ESWM 15.5.5-006, 16.5.0-429.

Affected products

  • Cisco Secure Email Gateway 15.5 and earlier; 16.0; 16.5 before 16.5.0-780
  • Cisco Secure Email and Web Manager 15.5 and earlier; 16.0; 16.5 before 16.5.0-429

Timeline

  • 2026-09-14: disclosed: Cisco advisory published as part of security hardening release
  • 2026-09-14: patched: Fixed releases available: ESA 15.5.5-014 / 16.5.0-780, ESWM 15.5.5-006 / 16.5.0-429

References

Related threats