Threat Advisory

Cisco Secure Email Flaws Allow Remote Execution and Access Bypasses

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Cisco Secure Email Gateway and Web Manager, which could allow remote execution or access bypasses. The affected versions include software releases 15.5, 16.0, and 16.5. Organizations should install updates immediately due to the high risk of exploitation.

CVE-2026-76440 (CVSS 9.8 — Critical): Path traversal flaws allow attackers to access restricted files.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Cisco Secure Email Gateway and Web Manager, which could allow remote execution or access bypasses. The affected versions include software releases 15.5, 16.0, and 16.5. Organizations should install updates immediately due to the high risk of exploitation.

CVE-2026-76440 (CVSS 9.8 — Critical): Path traversal flaws allow attackers to access restricted files.[emaillocker id="1283"]

CVE-2026-76441 (CVSS 9.8 — Critical): Improper access control enforcement enables unauthorized actions.

CVE-2026-20353 (CVSS 9.8 — Critical): Uncontrolled resource consumption and deserialization errors occur during data handling.

CVE-2026-76443 (CVSS 9.8 — Critical): Improper input neutralization covers command and SQL injections.

CVE-2026-76442 (CVSS 7.5 — High): Excessive resource consumption is caused by improper quantity validation.

These vulnerabilities collectively present serious operational risks to organizations worldwide, particularly those that have not applied updates.

RECOMMENDATIONS:

  • We recommend you to upgrade Cisco Secure Email Gateway and Cisco Secure Email and Web Manager to version 15.5.5-014 or 16.5.0-780.
  • We recommend you to install versions 15.5.5-006 or 16.5.0-429 for management appliance users.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu