Cyber & AI intelligence
Wasteland.
Briefs indexed2606
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-76441 2026-09-14

Cisco Secure Email Gateway and Secure Email and Web Manager Hit With Critical Access Control Flaw (cisco-sa-hardening-esa-dfCrfXkm)

"Cisco disclosed a critical (CVSS 9.8) improper access control weakness affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, found during an internal security review and tracked in advisory…"

Cisco disclosed a critical (CVSS 9.8) improper access control weakness affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, found during an internal security review and tracked in advisory cisco-sa-hardening-esa-dfCrfXkm.

What Is It

The advisory covers a group of vulnerabilities related to improper access control, classified under CWE-284 (Improper Access Control, a CWE Pillar). Cisco identified the issues internally as part of an ongoing proactive security and product quality review of the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering line. The review produced software hardening releases addressing multiple internally discovered vulnerabilities, of which this grouping is one.

A note on the identifier: this item has circulated as "CVE-2026-76441," but that number sits far outside the ID range CVE assignments for 2026 have actually reached, and it does not resolve to a published NVD record. Treat the CVE ID as unconfirmed and track this issue by the Cisco advisory ID until a valid identifier is published.

Why It Matters

Cisco PSIRT assigned a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

That vector describes the worst-case profile for a network-facing appliance: the flaw is reachable over the network, with low attack complexity, requiring no privileges and no user interaction. Successful exploitation carries high impact to confidentiality, integrity, and availability: the exploitability subscore is the maximum 3.9, with an impact subscore of 5.9.

These are email security appliances that sit in the mail path and hold management access to email and web policy, which makes an unauthenticated access control bypass a high-value target.

As of this writing, the issue does not appear in the CISA Known Exploited Vulnerabilities catalog, and the Cisco security advisory reports no evidence of exploitation in the wild. Cisco attributes discovery to its own internal review rather than to observed attacks.

What's Vulnerable

Cisco lists Cisco Secure Email and Web Manager as affected, with the advisory also covering Cisco Secure Email Gateway. Affected versions span the 12.x through 16.x trains, including:

Because there is no valid published CVE record behind this item yet, there are no CPE entries to match against; automated vulnerability scanners and asset inventories will not flag affected appliances. Version matching against the list above has to be done manually.

Patch Status

Cisco states the internal review "resulted in software hardening releases that address multiple internally discovered vulnerabilities." Administrators should consult the Cisco security advisory below for the specific fixed release mapping for their deployed version.

With no KEV listing, no federal remediation deadline applies under BOD 22-01. The CVSS 9.8 rating and the appliances' position in the mail path are reason enough to treat patching as urgent regardless.

Sources