CVE-2026-76440 CVE-2026-76441 CVE-2026-76443 CVE-2026-20353 CVE-2026-76442
Cisco Secure Email Gateway hardening release addresses critical and high-severity flaws (CVE-2026-76440 and others)
Cisco has issued a hardening release for Cisco Secure Email and Cisco Secure Email and Web Manager. Multiple flaws, four critical and one high, are reachable over the network without credentials. Cisco reports no known exploitation. No workarounds exist; apply the Cisco hardening release.
What happened
Cisco's engineering team carried out an internal security review of Cisco Secure Email and Cisco Secure Email and Web Manager, and has published a security hardening release. The bundled vulnerabilities are grouped under path traversal (CWE-23), improper access control (CWE-284), improper neutralization (CWE-707), improper control of a resource through its lifetime (CWE-664), and improper validation of specified quantity in input (CWE-1284). Four of the five records carry a CVSS 3.1 base score of 9.8; the fifth is scored 7.5.
All of the flaws have a network attack vector with low complexity, requiring no privileges and no user interaction. For the four critical issues, a successful exploit could provide high impact to confidentiality, integrity and availability. The high-severity issue affects availability only.
Cisco PSIRT states that it is not aware of any public announcements or malicious use of the vulnerabilities described in the advisory.
Who is affected
The affected releases listed in Cisco's advisory are:
Cisco Secure Email: 14.0.0-698, 13.5.1-277, 13.0.0-392, 14.2.0-620, 13.0.5-007, 13.5.4-038, 14.2.1-020, 14.3.0-032.
Cisco Secure Email and Web Manager: 13.6.2-023, 13.6.2-078, 13.0.0-249, 13.0.0-277, 13.8.1-052, 13.8.1-068, 13.8.1-074, 14.0.0-404.
These releases are named across the bundled CVE records; not every individual CVE necessarily applies to every product. If your deployment uses one of these releases, treat it as affected by this advisory.
What to do now
- Confirm whether any Cisco Secure Email or Cisco Secure Email and Web Manager deployments run one of the affected releases listed above.
- Apply the security hardening release from Cisco for your current software train. The specific fixed build numbers are not reproduced here; consult Cisco's advisory for the exact release for your deployment.
- There are no workarounds that address these vulnerabilities. If remediation cannot be completed immediately, restrict network reach to affected appliances and monitor for unexpected configuration changes.
- Prioritise appliances that are reachable from untrusted networks, given the network attack vector and lack of required credentials.
How to detect it
No vendor-supplied indicators of compromise are published in Cisco's advisory, and Cisco PSIRT reports no known exploitation. Because these flaws are reachable over the network with no credentials, start detection activity by identifying affected appliances that are reachable from untrusted networks and confirm they are in your asset inventory.
Beyond the patch
Beyond the patch itself, the immediate question is exposure: these flaws are reachable over the network with no credentials, so an affected appliance that is reachable from the wrong network segment is the real risk. Our Virtual CISO Services can help you map that exposure and build a governed remediation cycle. Cisco found these issues internally and published them as a bundle, which is also a reminder that your suppliers' patch cycles set your exposure window. Supply Chain Defense & Third-Party Risk tracks the vendor software you rely on and how quickly fixes reach you.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-76440 Cisco Secure Email | 14.0.0-698 13.5.1-277 13.0.0-392 14.2.0-620 13.0.5-007 13.5.4-038 14.2.1-020 14.3.0-032 | No fixed version listed yet |
| CVE-2026-76440 Cisco Secure Email and Web Manager | 13.6.2-023 13.6.2-078 13.0.0-249 13.0.0-277 13.8.1-052 13.8.1-068 13.8.1-074 14.0.0-404 | No fixed version listed yet |
| CVE-2026-76441 Cisco Secure Email and Web Manager | 13.6.2-023 13.6.2-078 13.0.0-249 13.0.0-277 13.8.1-052 13.8.1-068 13.8.1-074 14.0.0-404 | No fixed version listed yet |
| CVE-2026-76443 Cisco Secure Email | 14.0.0-698 13.5.1-277 13.0.0-392 14.2.0-620 13.0.5-007 13.5.4-038 14.2.1-020 14.3.0-032 | No fixed version listed yet |
| CVE-2026-76443 Cisco Secure Email and Web Manager | 13.6.2-023 13.6.2-078 13.0.0-249 13.0.0-277 13.8.1-052 13.8.1-068 13.8.1-074 14.0.0-404 | No fixed version listed yet |
| CVE-2026-20353 Cisco Secure Email | 14.0.0-698 13.5.1-277 13.0.0-392 14.2.0-620 13.0.5-007 13.5.4-038 14.2.1-020 14.3.0-032 | No fixed version listed yet |
| CVE-2026-76442 Cisco Secure Email | 14.0.0-698 13.5.1-277 13.0.0-392 14.2.0-620 13.0.5-007 13.5.4-038 14.2.1-020 14.3.0-032 | No fixed version listed yet |
| CVE-2026-76442 Cisco Secure Email and Web Manager | 13.6.2-023 13.6.2-078 13.0.0-249 13.0.0-277 13.8.1-052 13.8.1-068 13.8.1-074 14.0.0-404 | No fixed version listed yet |