Unauthenticated Improper Access Control in Cisco Secure Email Gateway and Web Manager
AI analysis
CVE-2026-76441 groups multiple internally discovered improper access control weaknesses (CWE-284) found during a proactive security review of Cisco Secure Email Gateway (the Email Security Appliance, ESA) and Cisco Secure Email and Web Manager (SMA). The 9.8 CVSS 3.1 score (network vector, low attack complexity, no privileges, no user interaction) indicates an unauthenticated remote attacker can trigger the flaw against an affected appliance and gain high-impact compromise of confidentiality, integrity, and availability — in practice, the type of access-control failure that can yield administrative control of the appliance and the mail flow it filters. Any organization running an affected release of these email security or management appliances is potentially exposed, especially where management or service interfaces are reachable from untrusted networks. Cisco addressed the issues in software hardening releases; there is no known public PoC, the CVE is not on CISA's KEV list, and no exploitation has been reported to date.
What to do: Apply Cisco's software hardening releases for Secure Email Gateway and Secure Email and Web Manager exactly as mapped in the PSIRT advisory, prioritizing appliances whose management or listener interfaces are reachable from untrusted networks. As an interim mitigation, restrict management access to trusted administrative subnets or VPN and enforce interface ACLs. Review audit logs and mail-flow policies for unexplained administrative changes or account creation that could indicate prior abuse.
Affected
| Cisco Secure Email Gateway (Email Security Appliance) | — |
| Cisco Secure Email and Web Manager (Security Management Appliance) | — |
Estimated exposure
large≈10,000–50,000 appliance deployments, with several thousand management interfaces historically internet-exposed — Cisco holds a leading share of the enterprise secure email gateway market and public internet scans (Shodan/Censys) have historically shown thousands of ESA/SMA interfaces exposed, supporting a tens-of-thousands installed-base estimate;…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.