Skip to content

CVE-2026-76440 CVE-2026-76441 CVE-2026-76443 CVE-2026-20353 CVE-2026-76442

Cisco Secure Email Gateway hardening release addresses critical and high-severity flaws (CVE-2026-76440 and others)

Critical 9.8 Vendor: Cisco Published

Cisco has issued a hardening release for Cisco Secure Email and Cisco Secure Email and Web Manager. Multiple flaws, four critical and one high, are reachable over the network without credentials. Cisco reports no known exploitation. No workarounds exist; apply the Cisco hardening release.

What happened

Cisco's engineering team carried out an internal security review of Cisco Secure Email and Cisco Secure Email and Web Manager, and has published a security hardening release. The bundled vulnerabilities are grouped under path traversal (CWE-23), improper access control (CWE-284), improper neutralization (CWE-707), improper control of a resource through its lifetime (CWE-664), and improper validation of specified quantity in input (CWE-1284). Four of the five records carry a CVSS 3.1 base score of 9.8; the fifth is scored 7.5.

All of the flaws have a network attack vector with low complexity, requiring no privileges and no user interaction. For the four critical issues, a successful exploit could provide high impact to confidentiality, integrity and availability. The high-severity issue affects availability only.

Cisco PSIRT states that it is not aware of any public announcements or malicious use of the vulnerabilities described in the advisory.

Who is affected

The affected releases listed in Cisco's advisory are:

Cisco Secure Email: 14.0.0-698, 13.5.1-277, 13.0.0-392, 14.2.0-620, 13.0.5-007, 13.5.4-038, 14.2.1-020, 14.3.0-032.

Cisco Secure Email and Web Manager: 13.6.2-023, 13.6.2-078, 13.0.0-249, 13.0.0-277, 13.8.1-052, 13.8.1-068, 13.8.1-074, 14.0.0-404.

These releases are named across the bundled CVE records; not every individual CVE necessarily applies to every product. If your deployment uses one of these releases, treat it as affected by this advisory.

What to do now

  1. Confirm whether any Cisco Secure Email or Cisco Secure Email and Web Manager deployments run one of the affected releases listed above.
  2. Apply the security hardening release from Cisco for your current software train. The specific fixed build numbers are not reproduced here; consult Cisco's advisory for the exact release for your deployment.
  3. There are no workarounds that address these vulnerabilities. If remediation cannot be completed immediately, restrict network reach to affected appliances and monitor for unexpected configuration changes.
  4. Prioritise appliances that are reachable from untrusted networks, given the network attack vector and lack of required credentials.

How to detect it

No vendor-supplied indicators of compromise are published in Cisco's advisory, and Cisco PSIRT reports no known exploitation. Because these flaws are reachable over the network with no credentials, start detection activity by identifying affected appliances that are reachable from untrusted networks and confirm they are in your asset inventory.

Beyond the patch

Beyond the patch itself, the immediate question is exposure: these flaws are reachable over the network with no credentials, so an affected appliance that is reachable from the wrong network segment is the real risk. Our Virtual CISO Services can help you map that exposure and build a governed remediation cycle. Cisco found these issues internally and published them as a bundle, which is also a reminder that your suppliers' patch cycles set your exposure window. Supply Chain Defense & Third-Party Risk tracks the vendor software you rely on and how quickly fixes reach you.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-76440
Cisco Secure Email
14.0.0-698
13.5.1-277
13.0.0-392
14.2.0-620
13.0.5-007
13.5.4-038
14.2.1-020
14.3.0-032
No fixed version listed yet
CVE-2026-76440
Cisco Secure Email and Web Manager
13.6.2-023
13.6.2-078
13.0.0-249
13.0.0-277
13.8.1-052
13.8.1-068
13.8.1-074
14.0.0-404
No fixed version listed yet
CVE-2026-76441
Cisco Secure Email and Web Manager
13.6.2-023
13.6.2-078
13.0.0-249
13.0.0-277
13.8.1-052
13.8.1-068
13.8.1-074
14.0.0-404
No fixed version listed yet
CVE-2026-76443
Cisco Secure Email
14.0.0-698
13.5.1-277
13.0.0-392
14.2.0-620
13.0.5-007
13.5.4-038
14.2.1-020
14.3.0-032
No fixed version listed yet
CVE-2026-76443
Cisco Secure Email and Web Manager
13.6.2-023
13.6.2-078
13.0.0-249
13.0.0-277
13.8.1-052
13.8.1-068
13.8.1-074
14.0.0-404
No fixed version listed yet
CVE-2026-20353
Cisco Secure Email
14.0.0-698
13.5.1-277
13.0.0-392
14.2.0-620
13.0.5-007
13.5.4-038
14.2.1-020
14.3.0-032
No fixed version listed yet
CVE-2026-76442
Cisco Secure Email
14.0.0-698
13.5.1-277
13.0.0-392
14.2.0-620
13.0.5-007
13.5.4-038
14.2.1-020
14.3.0-032
No fixed version listed yet
CVE-2026-76442
Cisco Secure Email and Web Manager
13.6.2-023
13.6.2-078
13.0.0-249
13.0.0-277
13.8.1-052
13.8.1-068
13.8.1-074
14.0.0-404
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.