Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file access via path traversal
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a path traversal flaw that allows an attacker to read or possibly write arbitrary files on the Cisco Secure Email or Secure Email and Web Manager. This weakness can expose sensitive configuration information or enable modification of files that may compromise credentials or other confidential data, and could be leveraged to alter system behavior. The flaw aligns with CWE-23, indicating a failure to properly validate path components, which can compromise confidentiality and integrity but is not explicitly described as enabling remote code execution.

Affected Systems

The affected products are Cisco Secure Email and Cisco Secure Email and Web Manager. No specific version range is documented, implying that all releases lacking the hardening patch are vulnerable.

Risk and Exploitability

The CVSS score of 9.8 categorizes the issue as critical. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, yet the severity and potential for damaging file access warrant urgent attention. Based on the description, it is inferred that attackers would likely need remote access to the web‑based administrative interface or API, and may require authenticated credentials to traverse directories, so misconfigured or exposed management ports increase the risk.

Generated by OpenCVE AI on September 21, 2026 at 00:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure Email and Secure Email and Web Manager update that includes the hardening release for CVE‑2026‑76440.
  • Restrict external access to the web‑based management console using firewall or proxy rules, allowing only trusted IP addresses to reach administrative ports.
  • Perform internal path‑traversal testing on the updated system to confirm that the file paths can no longer be manipulated.

Generated by OpenCVE AI on September 21, 2026 at 00:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Email
Cisco secure Email And Web Manager
Vendors & Products Cisco
Cisco secure Email
Cisco secure Email And Web Manager

Tue, 15 Sep 2026 18:30:00 +0000


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.
Title Cisco Secure Email Gateway Security Hardening Release
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cisco Secure Email Secure Email And Web Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-15T17:03:57.728Z

Reserved: 2026-08-19T12:02:03.635Z

Link: CVE-2026-76440

cve-icon Vulnrichment

Updated: 2026-09-15T17:03:57.728Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T17:17:50.520

Modified: 2026-09-15T18:19:12.950

Link: CVE-2026-76440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-23

    Relative Path Traversal