SB20260914146 - Multiple vulnerabilities in Cisco Secure Email Gateway and Secure Email and Web Manager



SB20260914146 - Multiple vulnerabilities in Cisco Secure Email Gateway and Secure Email and Web Manager

Published: September 14, 2026

Security Bulletin ID SB20260914146
CSH Severity
High
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 80% Medium 20%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-20353)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to improper control of a resource through its lifetime in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing input. A remote attacker can bypass implemented security restrictions and compromise the affected system.


2) Relative Path Traversal (CVE-ID: CVE-2026-76440)

CWE-ID: CWE-23 - Relative Path Traversal

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to path traversal in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing pathnames. A remote attacker can send a crafted pathname to compromise the affected system.


3) Improper access control (CVE-ID: CVE-2026-76441)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper access control in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when handling network requests. A remote attacker can send a specially crafted request and compromise the affected system.


4) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-76442)

CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to improper validation of specified quantity in input in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing numeric input. A remote attacker can send input containing an excessive numeric quantity and perform a denial of service attack.


5) Improper Neutralization (CVE-ID: CVE-2026-76443)

CWE-ID: CWE-707 - Improper Neutralization

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper neutralization in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing input. A remote user can send crafted input to compromise the affected system.


Remediation

Install update from vendor's website.