CVE-2026-76443
Received Received - Intake

Improper Neutralization in Cisco Secure Email Gateway

Vulnerability report for CVE-2026-76443, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Cisco Systems, Inc.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cisco secure_email_gateway *
cisco secure_email_and_web_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-707 The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-76443 is a vulnerability in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. It involves improper neutralization of input, which could allow attackers to bypass security controls or inject malicious content. The issue is classified under CWE-707, indicating weak input validation or sanitization.

Impact Analysis

This vulnerability could allow remote attackers to execute arbitrary code, gain unauthorized access, or disrupt services. It may lead to data breaches, system compromise, or denial of service due to the high CVSS score of 9.8, indicating critical severity.

Compliance Impact

The provided CVE data does not specify direct impacts on compliance with GDPR, HIPAA, or other standards. The vulnerability involves improper neutralization (CWE-707) with a high CVSS score (9.8), indicating potential for significant security risks that could indirectly affect compliance if exploited.

Mitigation Strategies

Apply the software hardening releases provided by Cisco for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager to address the vulnerabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76443. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart