Cisco Secure Email Gateway Hit by Critical Access Control Flaw CVE-2026-76441
A critical improper access control vulnerability, tracked as CVE-2026-76441, has been identified in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager versions 15.5 and earlier. India's CERT-In disclosed the flaw on 17 September 2026 via advisory CIVN-2026-0461, rating it critical alongside four related issues affecting the same product family. The vulnerability allows a remote, unauthenticated attacker to bypass authorization controls and gain unauthorized access to restricted functions or resources. Depending on the privileges tied to the compromised functionality, potential impacts include unauthorized data access, modification, or broader security consequences. No fixed release was specified in the CERT-In advisory, and administrators are urged to consult Cisco's official hardening advisory cisco-sa-hardening-esa-dfCrfXkm for remediation guidance.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in