ZeroHour

CVE-2026-76443

moderate

Critical Unauthenticated Input-Neutralization Flaws in Cisco Secure Email Gateway

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-76443 bundles multiple internally discovered improper-input-neutralization weaknesses (CWE-707 pillar) in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, found during a proactive Cisco engineering review rather than external reporting. The CVSS 9.8 vector (network, low complexity, no privileges, no user interaction) indicates the flaws can be triggered remotely by an unauthenticated attacker sending specially crafted input to the affected appliance. A successful attack yields high impact to confidentiality, integrity, and availability — consistent with prior severe issues in these products such as arbitrary file writes, OS command injection, or privilege escalation. Any organization running Cisco Secure Email Gateway or Secure Email and Web Manager without the latest hardening releases is affected. As of now there is no known public proof-of-concept, the flaw is not on CISA's KEV list, and no active exploitation has been reported.

What to do: Upgrade Cisco Secure Email Gateway and Secure Email and Web Manager to the hardened software releases specified in Cisco's advisory as soon as possible, since the flaw is unauthenticated and network-reachable. Until patched, restrict access to the management interface and web UI to trusted internal networks or VPN, and verify exposure with external port scans of your perimeter. Review logs for unexpected file writes, configuration changes, or command execution on affected appliances.

Affected
Cisco Secure Email Gateway (ESA)
Cisco Secure Email and Web Manager (SMA/ESWA)
Estimated exposure
moderateorder of 10^3–10^4 internet-exposed appliances; total enterprise deployments likely in the low tens of thousands — These are enterprise perimeter appliances, and public internet scans (e.g., Shodan) historically show on the order of ten thousand Cisco ESA/ESW Manager interfaces reachable online; exact counts vary by version so this is a rough…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.

Weakness
CWE-707
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco patches actively exploited Secure Email Gateway zero-day CVE-2026-76461 enabling unauthenticated root command execution; CISA adds it to KEV.

Cisco disclosed that a critical zero-day (CVE-2026-76461) in the email parsing logic of AsyncOS for Secure Email Gateway is being actively exploited, allowing unauthenticated remote attackers to execute arbitrary SQL statements that lead to root-level command execution on virtual and physical appliances. CISA added the flaw to its KEV catalog and ordered federal agencies to patch within three days, by September 17. Cisco also patched four other critical SEG/SEWM vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443) with no evidence of exploitation, and shared IOCs including suspicious SQL statements in mail_logs.