CISCO has fixed five vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. Four are rated critical with CVSS 3 scores of 9.8, while the remaining issue is high severity with a score of 7.5. The flaws affect software releases 15.5, 16.0 and 16.5, regardless of device configuration, but do not affect Cisco Secure Web Appliance.
The vulnerabilities include path traversal in CVE-2026-76440, improper access control in CVE-2026-76441, resource-consumption and deserialisation issues in CVE-2026-20353, command and SQL injection in CVE-2026-76443, and quantity-validation problems in CVE-2026-76442. Cisco said one vulnerability in the injection class is known to be actively exploited, although the supplied roundup lists no specific CVE as confirmed exploited. No public exploit code has been observed for the other flaws.
Cisco says there are no workarounds. Secure Email Gateway customers should upgrade to 15.5.5-014 or 16.5.0-780; users on 16.0 must migrate to a supported fixed release. Secure Email and Web Manager customers should install 15.5.5-006 or 16.5.0-429, with 16.0 users likewise required to migrate. Updates can be installed through the appliance’s web interface under **System Administration > System Upgrade**, or through the CLI using `upgrade` followed by `DOWNLOADINSTALL`; the appliance reboots after installation.