Vulnerability Intelligence Report
Cisco Secure Email Gateway Security Hardening Release
CVE-2026-76440
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:0.43%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-23 ↗Relative Path Traversal
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Cisco | Cisco Secure Email | 14.0.0-698 (affected), 13.5.1-277 (affected), 13.0.0-392 (affected), 14.2.0-620 (affected), 13.0.5-007 (affected), 13.5.4-038 (affected), 14.2.1-020 (affected), 14.3.0-032 (affected), 15.0.0-104 (affected), 15.0.1-030 (affected), 15.5.0-048 (affected), 15.5.1-055 (affected), 15.5.2-018 (affected), 16.0.0-050 (affected), 15.0.3-002 (affected), 16.0.0-054 (affected), 15.5.3-022 (affected), 16.0.1-017 (affected), 15.5.4-012 (affected), 16.0.4-016 (affected), 15.0.5-016 (affected), 16.0.2-112 (affected), 16.0.3-044 (affected), 15.5.5-014 (affected) |
| Cisco | Cisco Secure Email and Web Manager | 13.6.2-023 (affected), 13.6.2-078 (affected), 13.0.0-249 (affected), 13.0.0-277 (affected), 13.8.1-052 (affected), 13.8.1-068 (affected), 13.8.1-074 (affected), 14.0.0-404 (affected), 12.8.1-002 (affected), 14.1.0-227 (affected), 13.6.1-201 (affected), 14.2.0-203 (affected), 14.2.0-212 (affected), 12.8.1-021 (affected), 13.8.1-108 (affected), 14.2.0-224 (affected), 14.3.0-120 (affected), 15.0.0-334 (affected), 15.5.1-024 (affected), 15.5.1-029 (affected), 15.5.2-005 (affected), 16.0.0-195 (affected), 15.5.3-017 (affected), 16.0.1-010 (affected), 15.0.1-035 (affected), 16.0.2-088 (affected), 15.5.4-007 (affected), 15.0.2-007 (affected), 16.0.4-010 (affected), 16.0.3-016 (affected), 16.5.0-429 (affected), 15.5.5-006 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.428%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cisco Systems, Inc. · Hosted Service · USA |
| Reserved | 2026-08-19T12:02:03 |
| Published | 2026-09-14T16:08:50 |
| Last Updated | 2026-09-15T17:03:57 |
Community Chatter & Buzz