ZeroHour

CVE-2026-76440

large

Critical Path Traversal Flaws in Cisco Secure Email Gateway and Email/Web Manager

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-76440 groups multiple path traversal weaknesses (CWE Pillar CWE-23) found during Cisco's internal security review of Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, addressed via software hardening releases. With a CVSS 3.1 base score of 9.8 (network vector, low attack complexity, no privileges, no user interaction), a remote unauthenticated attacker could craft requests that escape intended directory boundaries to read, modify, or delete files on the appliance, potentially leading to full confidentiality, integrity, and availability impact. Any organization running an affected version of these email perimeter appliances is exposed, particularly since these gateways are designed to be internet-facing. No public proof-of-concept exists, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and no exploitation has been reported to date. Because the bugs were internally discovered, technical detail is limited and defenders should prioritize patching rather than await exploit intelligence.

What to do: Apply the software hardening release identified in Cisco's advisory for both Cisco Secure Email Gateway and Cisco Secure Email and Web Manager as soon as maintenance windows allow, given the unauthenticated 9.8 rating. Restrict the web management interface to trusted admin networks or VPN so only SMTP ports are exposed to the internet. Review appliance logs for unexpected file access, anomalous admin activity, or unfamiliar file modifications that could indicate prior probing.

Affected
Cisco Secure Email GatewayAffected versions not enumerated in the advisory summary; fixed in Cisco's software hardening release for this CVE
Cisco Secure Email and Web ManagerAffected versions not enumerated in the advisory summary; fixed in Cisco's software hardening release for this CVE
Estimated exposure
largetens of thousands of internet-facing appliances (order 10,000-100,000 deployments) — Cisco email security gateways are perimeter appliances whose SMTP and management interfaces are frequently internet-reachable, and public scan engines have historically shown tens of thousands of Cisco ESA/SEWM instances online, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.

Weakness
CWE-23
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco patches actively exploited Secure Email Gateway zero-day CVE-2026-76461 enabling unauthenticated root command execution; CISA adds it to KEV.

Cisco disclosed that a critical zero-day (CVE-2026-76461) in the email parsing logic of AsyncOS for Secure Email Gateway is being actively exploited, allowing unauthenticated remote attackers to execute arbitrary SQL statements that lead to root-level command execution on virtual and physical appliances. CISA added the flaw to its KEV catalog and ordered federal agencies to patch within three days, by September 17. Cisco also patched four other critical SEG/SEWM vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443) with no evidence of exploitation, and shared IOCs including suspicious SQL statements in mail_logs.