Improper access control in Cisco Secure Email and Web Manager and Secure Email Gateway - CVE-2026-76441

 

Improper access control in Cisco Secure Email and Web Manager and Secure Email Gateway - CVE-2026-76441

Published: September 14, 2026


Vulnerability identifier: #VU149713
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76441
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper access control in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when handling network requests. A remote attacker can send a specially crafted request and compromise the affected system.


Affected software

Cisco Secure Email and Web Manager
Secure Email Gateway

How to mitigate CVE-2026-76441

Install security update from vendor's website.

Cisco Secure Email and Web Manager - addressed in versions 15.5.5-006, 16.5.0-429
Secure Email Gateway - addressed in versions 15.5.5-014, 16.5.0-780

External References

Related Security Bulletins