Skip to content
CiscoCVE-2026-76441

Cisco Secure Email and Web Manager: improper access control

Critical9.8CVE-2026-76441 · Published Sep 14, 2026 · updated Sep 15, 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Secure Email and Web Manager
Product
<= 13.6.2-023No fix yet
<= 13.6.2-078No fix yet
<= 13.0.0-249No fix yet
<= 13.0.0-277No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Identity Services Engine Software: remote code execution
Critical9.9Sep 16
Cisco Secure Email: remote code execution
Critical9.8Sep 14
Cisco Secure Email: path traversal
Critical9.8Sep 14
Cisco Secure Email: improper quantity validation
High7.5Sep 14
As part of Cisco's ongoing commitment to proactive security and product quality
Critical9.8Sep 14
As part of Cisco's ongoing commitment to proactive security and product quality
Critical9.8Sep 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.