Junglewise Threat Intelligence

CVE-2026-76443: Cisco Secure Email Gateway improper neutralization vulnerability

CVE-2026-76443 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Technologies: Cisco Secure Email and Web Manager, Cisco Secure Email Gateway. Vendors: Cisco.

Executive brief

Cisco Secure Email Gateway and Secure Email and Web Manager are critical email security appliances that protect organizational communications from threats. CVE-2026-76443 represents a class of improper neutralization vulnerabilities (including SQL injection) that allow unauthenticated remote attackers to execute malicious code or commands on the appliances, potentially leading to complete compromise of email security, data theft, and service disruption. At least one vulnerability in this class is known to be actively exploited in the wild.

Technical details

CVE-2026-76443 encompasses multiple improper neutralization vulnerabilities grouped under CWE-707, including SQL injection, command injection, and code injection flaws. The vulnerabilities affect Cisco Secure Email Gateway and Cisco Secure Email and Web Manager regardless of configuration. These are network-reachable vulnerabilities requiring no authentication or user interaction (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Attackers can achieve remote code execution or arbitrary command execution to fully compromise the appliance. Cisco has released patched versions: Secure Email Gateway 15.5.5-014+ and 16.5.0-780+; Secure Email and Web Manager 15.5.5-006+ and 16.5.0-429+. No workarounds are available.

Affected products

  • Cisco Secure Email Gateway 15.5 and earlier, 16.0, 16.5 before 16.5.0-780
  • Cisco Secure Email and Web Manager 15.5 and earlier, 16.0, 16.5 before 16.5.0-429

Timeline

  • 2026-09-14: disclosed: CVE-2026-76443 published
  • exploited: At least one vulnerability in this CWE-707 class is known to be actively exploited
  • patched: Fixed releases available: SEG 15.5.5-014, 16.5.0-780; SEWM 15.5.5-006, 16.5.0-429

References

Related threats