Improper access control in Cisco Secure Email and Web Manager and Secure Email Gateway - CVE-2026-76441
Published: September 14, 2026
Vulnerability identifier: #VU149713
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76441
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper access control in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when handling network requests. A remote attacker can send a specially crafted request and compromise the affected system.
Affected software
Cisco Secure Email and Web Manager
Secure Email Gateway
Secure Email Gateway
How to mitigate CVE-2026-76441
Install security update from vendor's website.
Cisco Secure Email and Web Manager - addressed in versions 15.5.5-006, 16.5.0-429
Secure Email Gateway - addressed in versions 15.5.5-014, 16.5.0-780
Secure Email Gateway - addressed in versions 15.5.5-014, 16.5.0-780