TL;DR
Cisco resolved five security flaws affecting its email gateways and management controllers. Four vulnerabilities carry critical CVSS scores of 9.8, allowing remote execution or access bypasses. Organizations should install updates immediately because one related injection flaw faces active exploitation.
- Total: 5 CVEs
- Severity: 4 Critical · 1 High
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical · CVSSv3) — CVE-2026-76440
- Action: Apply the latest security updates now
Track every Cisco CVE the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-76440 | 9.8 | Gateway Security Hardening Release | Not exploited |
| CVE-2026-76441 | 9.8 | Secure Email Gateway Security Hardening Release | Not exploited |
| CVE-2026-20353 | 9.8 | Gateway Security Hardening Release | Not exploited |
| CVE-2026-76443 | 9.8 | Gateway Security Hardening Release | Not exploited |
| CVE-2026-76442 | 7.5 | Gateway Security Hardening Release | Not exploited |
Why This Matters
Industry estimates indicate that tens of thousands of organizations deploy Cisco email gateways worldwide. Therefore, unpatched Cisco Secure Email vulnerabilities present serious operational risks. If threat actors exploit these vulnerabilities, they can intercept confidential corporate communications. Furthermore, attackers can gain footholds into corporate perimeters and compromise management systems.
How the Attack Works
The vulnerabilities span several weakness classes across the appliance software stack. First, CVE-2026-76440 involves path traversal flaws that allow attackers to access restricted files. In addition, CVE-2026-76441 enables unauthorized actions through improper access control enforcement.
Meanwhile, CVE-2026-20353 permits uncontrolled resource consumption and deserialization errors during data handling. Another critical flaw, CVE-2026-76443, stems from improper input neutralization covering command and SQL injections. Cisco confirmed that “one vulnerability that belongs to this vulnerability class is known to be actively exploited.” Finally, CVE-2026-76442 involves improper quantity validation that can drive excessive resource consumption.
Affected Versions
These vulnerabilities impact Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The advisory states, “These vulnerabilities affect Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, regardless of device configuration.” Specifically, the flaws affect software releases 15.5, 16.0, and 16.5. Cisco confirmed that these vulnerabilities do not affect Cisco Secure Web Appliance. Aside from the noted injection flaw, researchers have observed no public exploit code.
Patch and Mitigation Steps
Administrators must apply official vendor updates without delay. The advisory states, “There are no workarounds that address these vulnerabilities.” Gateway users should upgrade to versions 15.5.5-014 or 16.5.0-780. Similarly, management appliance users must install versions 15.5.5-006 or 16.5.0-429. Administrators running version 16.0 should migrate directly to a supported release.
| Cisco Secure Email Gateway Release | First Fixed Release |
|---|---|
| 15.5 and earlier | 15.5.5-014 |
| 16.0 | Migrate to a fixed release. |
| 16.5 | 16.5.0-780 |
| Cisco Secure Email and Web Manager Release | First Fixed Release |
|---|---|
| 15.5 and earlier | 15.5.5-006 |
| 16.0 | Migrate to a fixed release. |
| 16.5 | 16.5.0-429 |
The software can be upgraded over the network by using the System Upgrade options in the web-based management interface of the appliance.
To upgrade a device by using the web-based management interface, do the following:
- Choose System Administration > System Upgrade.
- Click Upgrade Options.
- Click Download and Install.
- Choose a release to upgrade to.
- In the Upgrade Preparation area, choose the appropriate options.
- Click Proceed to begin the upgrade. A progress bar displays the status of the upgrade.
After the upgrade is complete, the device reboots.
To upgrade a device by using the CLI, do the following:
- Run upgrade.
- Enter DOWNLOADINSTALL.
- Choose a release to upgrade to.
- Choose the appropriate options throughout the upgrade process.
After the upgrade is complete, the device reboots.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!