Improper Validation of Specified Quantity in Input in Cisco Secure Email and Web Manager and Secure Email Gateway - CVE-2026-76442

 

Improper Validation of Specified Quantity in Input in Cisco Secure Email and Web Manager and Secure Email Gateway - CVE-2026-76442

Published: September 14, 2026


Vulnerability identifier: #VU149716
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76442
CWE-ID: CWE-1284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to improper validation of specified quantity in input in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager when processing numeric input. A remote attacker can send input containing an excessive numeric quantity and perform a denial of service attack.


Affected software

Cisco Secure Email and Web Manager
Secure Email Gateway

How to mitigate CVE-2026-76442

Install security update from vendor's website.

Cisco Secure Email and Web Manager - addressed in versions 15.5.5-006, 16.5.0-429
Secure Email Gateway - addressed in versions 15.5.5-014, 16.5.0-780

External References

Related Security Bulletins