Cisco disclosed a critical (CVSS 9.8) improper access control weakness affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, found during an internal security review and tracked in advisory cisco-sa-hardening-esa-dfCrfXkm.
What Is It
The advisory covers a group of vulnerabilities related to improper access control, classified under CWE-284 (Improper Access Control, a CWE Pillar). Cisco identified the issues internally as part of an ongoing proactive security and product quality review of the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering line. The review produced software hardening releases addressing multiple internally discovered vulnerabilities, of which this grouping is one.
A note on the identifier: this item has circulated as "CVE-2026-76441," but that number sits far outside the ID range CVE assignments for 2026 have actually reached, and it does not resolve to a published NVD record. Treat the CVE ID as unconfirmed and track this issue by the Cisco advisory ID until a valid identifier is published.
Why It Matters
Cisco PSIRT assigned a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
That vector describes the worst-case profile for a network-facing appliance: the flaw is reachable over the network, with low attack complexity, requiring no privileges and no user interaction. Successful exploitation carries high impact to confidentiality, integrity, and availability: the exploitability subscore is the maximum 3.9, with an impact subscore of 5.9.
These are email security appliances that sit in the mail path and hold management access to email and web policy, which makes an unauthenticated access control bypass a high-value target.
As of this writing, the issue does not appear in the CISA Known Exploited Vulnerabilities catalog, and the Cisco security advisory reports no evidence of exploitation in the wild. Cisco attributes discovery to its own internal review rather than to observed attacks.
What's Vulnerable
Cisco lists Cisco Secure Email and Web Manager as affected, with the advisory also covering Cisco Secure Email Gateway. Affected versions span the 12.x through 16.x trains, including:
- 12.8.1-002, 12.8.1-021
- 13.0.0-249, 13.0.0-277, 13.6.1-201, 13.6.2-023, 13.6.2-078, 13.8.1-052, 13.8.1-068, 13.8.1-074, 13.8.1-108
- 14.0.0-404, 14.1.0-227, 14.2.0-203, 14.2.0-212, 14.2.0-224, 14.3.0-120
- 15.0.0-334, 15.0.1-035, 15.0.2-007, 15.5.1-024, 15.5.1-029, 15.5.2-005, 15.5.3-017, 15.5.4-007
- 16.0.0-195, 16.0.1-010, 16.0.2-088, 16.0.3-016, 16.0.4-010
Because there is no valid published CVE record behind this item yet, there are no CPE entries to match against; automated vulnerability scanners and asset inventories will not flag affected appliances. Version matching against the list above has to be done manually.
Patch Status
Cisco states the internal review "resulted in software hardening releases that address multiple internally discovered vulnerabilities." Administrators should consult the Cisco security advisory below for the specific fixed release mapping for their deployed version.
With no KEV listing, no federal remediation deadline applies under BOD 22-01. The CVSS 9.8 rating and the appliances' position in the mail path are reason enough to treat patching as urgent regardless.
Sources
- Cisco Security Advisory (cisco-sa-hardening-esa-dfCrfXkm): https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
- NVD lookup for the circulated identifier (does not currently resolve): https://nvd.nist.gov/vuln/detail/CVE-2026-76441