ZeroHour

CVE-2026-76441

large1

Unauthenticated Improper Access Control in Cisco Secure Email Gateway and Web Manager

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-76441 groups multiple internally discovered improper access control weaknesses (CWE-284) found during a proactive security review of Cisco Secure Email Gateway (the Email Security Appliance, ESA) and Cisco Secure Email and Web Manager (SMA). The 9.8 CVSS 3.1 score (network vector, low attack complexity, no privileges, no user interaction) indicates an unauthenticated remote attacker can trigger the flaw against an affected appliance and gain high-impact compromise of confidentiality, integrity, and availability — in practice, the type of access-control failure that can yield administrative control of the appliance and the mail flow it filters. Any organization running an affected release of these email security or management appliances is potentially exposed, especially where management or service interfaces are reachable from untrusted networks. Cisco addressed the issues in software hardening releases; there is no known public PoC, the CVE is not on CISA's KEV list, and no exploitation has been reported to date.

What to do: Apply Cisco's software hardening releases for Secure Email Gateway and Secure Email and Web Manager exactly as mapped in the PSIRT advisory, prioritizing appliances whose management or listener interfaces are reachable from untrusted networks. As an interim mitigation, restrict management access to trusted administrative subnets or VPN and enforce interface ACLs. Review audit logs and mail-flow policies for unexplained administrative changes or account creation that could indicate prior abuse.

Affected
Cisco Secure Email Gateway (Email Security Appliance)
Cisco Secure Email and Web Manager (Security Management Appliance)
Estimated exposure
large≈10,000–50,000 appliance deployments, with several thousand management interfaces historically internet-exposed — Cisco holds a leading share of the enterprise secure email gateway market and public internet scans (Shodan/Censys) have historically shown thousands of ESA/SMA interfaces exposed, supporting a tens-of-thousands installed-base estimate;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco patches actively exploited Secure Email Gateway zero-day CVE-2026-76461 enabling unauthenticated root command execution; CISA adds it to KEV.

Cisco disclosed that a critical zero-day (CVE-2026-76461) in the email parsing logic of AsyncOS for Secure Email Gateway is being actively exploited, allowing unauthenticated remote attackers to execute arbitrary SQL statements that lead to root-level command execution on virtual and physical appliances. CISA added the flaw to its KEV catalog and ordered federal agencies to patch within three days, by September 17. Cisco also patched four other critical SEG/SEWM vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443) with no evidence of exploitation, and shared IOCs including suspicious SQL statements in mail_logs.