CiscoCVE-2026-76441
Cisco Secure Email and Web Manager: improper access control
Critical9.8CVE-2026-76441 · Published Sep 14, 2026 · updated Sep 15, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco Secure Email and Web Manager Product | <= 13.6.2-023 | No fix yet |
| <= 13.6.2-078 | No fix yet | |
| <= 13.0.0-249 | No fix yet | |
| <= 13.0.0-277 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-284
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Cisco Identity Services Engine Software: remote code execution | Critical9.9 | No fix yet |
| Sep 14 | Cisco Secure Email: remote code execution | Critical9.8 | No fix yet |
| Sep 14 | Cisco Secure Email: path traversal | Critical9.8 | No fix yet |
| Sep 14 | Cisco Secure Email: improper quantity validation | High7.5 | No fix yet |
| Sep 14 | As part of Cisco's ongoing commitment to proactive security and product quality | Critical9.8 | No fix yet |
| Sep 14 | As part of Cisco's ongoing commitment to proactive security and product quality | Critical9.8 | No fix yet |