[CIVN-2026-0461] Multiple Vulnerabilities in Cisco Secure Email Gateway

By Published On: September 18, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Cisco Secure Email Gateway


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Cisco Secure Email Gateway 15.5 and earlier 

Cisco Secure Email and Web Manager 15.5 and earlier

Overview


Multiple vulnerabilities have been reported in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that could allow an attacker to gain unauthorized access to files outside restricted directories, bypass authorization controls and access restricted resources, inject malicious input, consume excessive system resources, degrade service availability, or cause a denial-of-service (DoS) condition on the targeted system.


Target Audience:

All IT administrators and individuals using Cisco products.


Risk Assessment:

Risk of information disclosure.


Impact Assessment:

Potential for disclosure of sensitive information and compromise of confidentiality.


Description


1. Path Traversal Vulnerability ( CVE-2026-76440   )


This vulnerability exists due to improper validation and resolution of pathnames and symbolic links, which could allow an unauthenticated, remote attacker to bypass intended directory restrictions.

Successful exploitation of this vulnerability could allow an attacker to access, read, or modify files outside the designated restricted directories, potentially resulting in unauthorized disclosure or manipulation of sensitive system files.


2. Improper Access Control Vulnerability ( CVE-2026-76441   )


This vulnerability could allow a remote, unauthenticated attacker to bypass intended authentication or authorization controls and gain unauthorized access to restricted resources or functionality.

Successful exploitation of this vulnerability could enable an attacker to access resources or perform functions that should be restricted to authenticated or authorized users, potentially resulting in unauthorized data access, modification, or other security impacts depending on the privileges associated with the affected functionality.


3. Input Validation of Quantity Vulnerability ( CVE-2026-76442   )


This vulnerability exists due to an input validation, which could allow a remote attacker to submit unbounded or excessively large numeric input.

Successful exploitation of this vulnerability could allow excessive consumption of system resources, potentially degrading service availability or causing the affected system to become unresponsive, resulting in a Denial-of-Service (DoS) condition.


4. Improper Neutralization Vulnerability ( CVE-2026-76443   )


This vulnerability could allow an attacker to inject malicious input into security-sensitive processing contexts, including command, SQL, code/evaluation, or cross-site scripting (XSS) contexts.

Successful exploitation of this vulnerability could allow an attacker to execute unauthorized commands or code, access or manipulate data, or perform other unauthorized actions within the context of the affected component.


5. Resource Lifetime Control Vulnerability ( CVE-2026-20353   )


This vulnerability could allow an attacker to trigger uncontrolled resource consumption through improper resource management, unsafe deserialization, or improper resource initialization.

Successful exploitation of this vulnerability could allow excessive consumption of system resources, service degradation, or service disruption, potentially causing the affected system to become unresponsive and resulting in a Denial-of-Service (DoS) condition.


Solution


Apply appropriate updates as mentioned in Cisco Advisory

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm



Vendor Information


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm


References


CISCO

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm


CVE Name

CVE-2026-76440

CVE-2026-76441

CVE-2026-76442

CVE-2026-76443

CVE-2026-20353




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: [email protected]

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtP1wACgkQ3jCgcSdc

ys9ezw/9ElCU5HHk30jdTAEWNM5xrPf/mxP3eDdL75pNSO2Hmjz6sS625BN6nqvr

U6bXb+ovgNK2XWp0R4e4hfc0eUckTgXLPcfta5QoG+OWUpWY73kgt141jsDm6Dlc

r1gc0v89gSxBuShRyg/1Ac+tZBs8GF+x1XW0+U8MR5mThfYCXy74xy4PVdl89jTy

NrMP+kRq0qPpLq986h7C7gk02DshsiPX55lky9UAMVspaZMxlpcruIPDDXCpHWcW

G27quG3wHno7mjzDKtyFGlMSWX8o/9MQC149xB1bI7sY+6sgEn8WupoANHr19Kp0

hd5/yOK549BJW2KDGpuTNfrPQZJijds1ZZGXq2FNP+T9OBQi9oy2RDEpAOk/4vLe

1fezHOhsWw6APCSd0VnhUkJZqJ3Gk4HvRyFTdhEOqsQh15uwZGbp8+ndatKCZz4p

dgNds6cIvyrXAi/IC8WgX2EN4IkGv1fltl6hc1/znd2B9eOAzNKI1ZJMo1uCEcmP

HQRUDx7jhQ8Ro5ij1YtylO4no9GgDXkltLFrINYUUlv/brJrUdJMhAikKZij6jRr

+NIhpesFMamniLlSi94OxOojS3Cg3SeXVA6ySWpYQGbW7D91XpG4CiVT/HQ5u9ri

CuGMvshfEPsL/5BhLMKzg0jeIB7xhB2F1DrgwLgBCTXM57MXwW4=

=XXrI

—–END PGP SIGNATURE—–

Share this article