Cisco Patches Critical Input Validation Flaw in Secure Email Gateway Products
Cisco released fixes on September 14, 2026, for five vulnerabilities in its email security products, including CVE-2026-76442, an input validation flaw scored 7.5 affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The vulnerability allows a remote attacker to submit unbounded numeric input, potentially exhausting system resources and causing denial of service. India's CERT-In republished the advisory on September 17, 2026, as CIVN-2026-0461 with a critical overall rating. Affected versions include 15.5 and earlier, as well as 16.0 and 16.5, regardless of device configuration. Cisco offers no workaround, and the only remediation is applying the vendor update via a CLI-initiated install that reboots the appliance upon completion.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in