Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Improper Input Validation
Action: Apply Hardening
AI Analysis

Impact

The vulnerability is caused by a failure to properly validate quantity values supplied in user input on Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The flaw is classified as an input‑validation weakness (CWE‑1284) and could allow an attacker to send or influence quantity parameters that do not conform to expected ranges, potentially causing the software to behave unexpectedly or fail to process requests correctly.

Affected Systems

The affected products are Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. No specific version information is provided in the advisory; all deployed instances of these products are potentially impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level. The EPSS score of < 1% means the likelihood of exploitation is very low but not zero. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through web or service interfaces where quantity parameters are accepted; this inference is drawn from the description that improperly validated quantity values can be supplied by users.

Generated by OpenCVE AI on September 21, 2026 at 00:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco Secure Email and Cisco Secure Email and Web Manager hardening releases as distributed in the Cisco advisory
  • Follow the installation instructions provided in the Cisco advisory to update the gateway software with the latest hardening patches
  • Review and enforce input‑validation rules for quantity parameters on the platform to ensure only valid ranges are accepted

Generated by OpenCVE AI on September 21, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Email
Cisco secure Email And Web Manager
Vendors & Products Cisco
Cisco secure Email
Cisco secure Email And Web Manager

Tue, 15 Sep 2026 18:30:00 +0000


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.
Title Cisco Secure Email Gateway Security Hardening Release
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Secure Email Secure Email And Web Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-16T03:55:36.952Z

Reserved: 2026-08-19T12:02:03.635Z

Link: CVE-2026-76442

cve-icon Vulnrichment

Updated: 2026-09-15T17:03:58.176Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T17:17:50.810

Modified: 2026-09-16T04:18:41.067

Link: CVE-2026-76442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input