Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76440— Cisco Secure Email Gateway Security Hardening Release

Quick assessment

Affected
Cisco Cisco Secure Email
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

作为思科对主动安全与产品质量的持续承诺的一部分,思科安全邮件网关(Secure Email Gateway)和思科安全邮件与 Web 管理器(Secure Email and Web Manager)工程团队进行了一次全面的内部安全审查。此次审查促成了多个软件加固版本,以修复若干内部发现的安全漏洞。 由 CVE-2026-76440 跟踪的漏洞与路径遍历(path traversal)问题相关,这些问题被归类在通用缺陷枚举(CWE)体系中的 CWE-23 大类下。

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 56

VendorProduct Version RangeStatus
Cisco Cisco Secure Email 14.0.0-698 affected
13.5.1-277 affected
13.0.0-392 affected
14.2.0-620 affected
13.0.5-007 affected
13.5.4-038 affected
14.2.1-020 affected
14.3.0-032 affected
… +16 more rows
Cisco Cisco Secure Email and Web Manager 13.6.2-023 affected
13.6.2-078 affected
13.0.0-249 affected
13.0.0-277 affected
13.8.1-052 affected
13.8.1-068 affected
13.8.1-074 affected
14.0.0-404 affected
… +24 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76440

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Secure Email Gateway Security Hardening Release
Source: CVE Program / CVE List V5
Vulnerability Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
相对路径遍历
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco Cisco Secure Email 14.0.0-698 -
Cisco Cisco Secure Email and Web Manager 13.6.2-023 -

II. Public POCs for CVE-2026-76440

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76440

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76440 (1)

Same Patch Batch · Cisco · 2026-09-14 · 6 CVEs total

CVE-2026-76461 9.8 CRITICAL Cisco Secure Email Gateway SQL Injection Vulnerability
CVE-2026-76443 9.8 CRITICAL Cisco Secure Email Gateway Security Hardening Release
CVE-2026-76441 9.8 CRITICAL Cisco Secure Email Gateway Security Hardening Release
CVE-2026-20353 9.8 CRITICAL Cisco Secure Email Gateway Security Hardening Release
CVE-2026-76442 7.5 HIGH Cisco Secure Email Gateway Security Hardening Release

IV. Related Vulnerabilities

V. Comments for CVE-2026-76440

No comments yet


Leave a comment