
[CIVN-2026-0461] Multiple Vulnerabilities in Cisco Secure Email Gateway
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Cisco Secure Email Gateway
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Cisco Secure Email Gateway 15.5 and earlier
Cisco Secure Email and Web Manager 15.5 and earlier
Overview
Multiple vulnerabilities have been reported in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that could allow an attacker to gain unauthorized access to files outside restricted directories, bypass authorization controls and access restricted resources, inject malicious input, consume excessive system resources, degrade service availability, or cause a denial-of-service (DoS) condition on the targeted system.
Target Audience:
All IT administrators and individuals using Cisco products.
Risk Assessment:
Risk of information disclosure.
Impact Assessment:
Potential for disclosure of sensitive information and compromise of confidentiality.
Description
1. Path Traversal Vulnerability ( CVE-2026-76440 )
This vulnerability exists due to improper validation and resolution of pathnames and symbolic links, which could allow an unauthenticated, remote attacker to bypass intended directory restrictions.
Successful exploitation of this vulnerability could allow an attacker to access, read, or modify files outside the designated restricted directories, potentially resulting in unauthorized disclosure or manipulation of sensitive system files.
2. Improper Access Control Vulnerability ( CVE-2026-76441 )
This vulnerability could allow a remote, unauthenticated attacker to bypass intended authentication or authorization controls and gain unauthorized access to restricted resources or functionality.
Successful exploitation of this vulnerability could enable an attacker to access resources or perform functions that should be restricted to authenticated or authorized users, potentially resulting in unauthorized data access, modification, or other security impacts depending on the privileges associated with the affected functionality.
3. Input Validation of Quantity Vulnerability ( CVE-2026-76442 )
This vulnerability exists due to an input validation, which could allow a remote attacker to submit unbounded or excessively large numeric input.
Successful exploitation of this vulnerability could allow excessive consumption of system resources, potentially degrading service availability or causing the affected system to become unresponsive, resulting in a Denial-of-Service (DoS) condition.
4. Improper Neutralization Vulnerability ( CVE-2026-76443 )
This vulnerability could allow an attacker to inject malicious input into security-sensitive processing contexts, including command, SQL, code/evaluation, or cross-site scripting (XSS) contexts.
Successful exploitation of this vulnerability could allow an attacker to execute unauthorized commands or code, access or manipulate data, or perform other unauthorized actions within the context of the affected component.
5. Resource Lifetime Control Vulnerability ( CVE-2026-20353 )
This vulnerability could allow an attacker to trigger uncontrolled resource consumption through improper resource management, unsafe deserialization, or improper resource initialization.
Successful exploitation of this vulnerability could allow excessive consumption of system resources, service degradation, or service disruption, potentially causing the affected system to become unresponsive and resulting in a Denial-of-Service (DoS) condition.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
CVE Name
CVE-2026-76440
CVE-2026-76441
CVE-2026-76442
CVE-2026-76443
CVE-2026-20353
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: [email protected]
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtP1wACgkQ3jCgcSdc
ys9ezw/9ElCU5HHk30jdTAEWNM5xrPf/mxP3eDdL75pNSO2Hmjz6sS625BN6nqvr
U6bXb+ovgNK2XWp0R4e4hfc0eUckTgXLPcfta5QoG+OWUpWY73kgt141jsDm6Dlc
r1gc0v89gSxBuShRyg/1Ac+tZBs8GF+x1XW0+U8MR5mThfYCXy74xy4PVdl89jTy
NrMP+kRq0qPpLq986h7C7gk02DshsiPX55lky9UAMVspaZMxlpcruIPDDXCpHWcW
G27quG3wHno7mjzDKtyFGlMSWX8o/9MQC149xB1bI7sY+6sgEn8WupoANHr19Kp0
hd5/yOK549BJW2KDGpuTNfrPQZJijds1ZZGXq2FNP+T9OBQi9oy2RDEpAOk/4vLe
1fezHOhsWw6APCSd0VnhUkJZqJ3Gk4HvRyFTdhEOqsQh15uwZGbp8+ndatKCZz4p
dgNds6cIvyrXAi/IC8WgX2EN4IkGv1fltl6hc1/znd2B9eOAzNKI1ZJMo1uCEcmP
HQRUDx7jhQ8Ro5ij1YtylO4no9GgDXkltLFrINYUUlv/brJrUdJMhAikKZij6jRr
+NIhpesFMamniLlSi94OxOojS3Cg3SeXVA6ySWpYQGbW7D91XpG4CiVT/HQ5u9ri
CuGMvshfEPsL/5BhLMKzg0jeIB7xhB2F1DrgwLgBCTXM57MXwW4=
=XXrI
—–END PGP SIGNATURE—–


