SB20260914146 - Multiple vulnerabilities in Cisco Secure Email Gateway and Secure Email and Web Manager
Published: September 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-20353)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improper control of a resource through its lifetime in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing input. A remote attacker can bypass implemented security restrictions and compromise the affected system.
2) Relative Path Traversal (CVE-ID: CVE-2026-76440)
CWE-ID: CWE-23 - Relative Path Traversal
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to path traversal in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing pathnames. A remote attacker can send a crafted pathname to compromise the affected system.
3) Improper access control (CVE-ID: CVE-2026-76441)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper access control in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when handling network requests. A remote attacker can send a specially crafted request and compromise the affected system.
4) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-76442)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to improper validation of specified quantity in input in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing numeric input. A remote attacker can send input containing an excessive numeric quantity and perform a denial of service attack.
5) Improper Neutralization (CVE-ID: CVE-2026-76443)
CWE-ID: CWE-707 - Improper Neutralization
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper neutralization in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing input. A remote user can send crafted input to compromise the affected system.
Remediation
Install update from vendor's website.