Impact
The vulnerability identified by CVE‑2026‑76443 arises from improper neutralization of input within Cisco Secure Email Gateway and Cisco Secure Email and Web Manager products. Improper neutralization can allow attackers to supply specially crafted data that bypasses the system’s expected sanitization process, potentially leading to the execution of arbitrary code or other unauthorized actions. The flaw is directly tied to CWE‑707, highlighting the risk of malicious content being interpreted as executable by the application.
Affected Systems
Products impacted are Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The advisory does not specify particular software versions, but the issue applies to all builds that have not been updated with the latest hardening release.
Risk and Exploitability
The CVSS score of 9.8 indicates a critically high severity. The EPSS score of 0.00388 (under 1%) indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting that publicly known exploits have not yet been observed. Because the weakness involves improper neutralization that can be leveraged from external network traffic, the attack vector is inferred to be remote, and the vulnerability can potentially be exploited by adversaries with network access to the email gateway.
OpenCVE Enrichment