CVE-2026-76441: Access Control Bypass in Cisco Secure Email Gateway
CERT-In rated CVE-2026-76441 as CRITICAL: an improper access control flaw in Cisco Secure Email Gateway 15.5 and earlier lets a remote unauthenticated attacker bypass authorization and reach restricted functions. Cisco published hardening advisory cisco-sa-hardening-esa-dfCrfXkm.
- Affects Cisco Secure Email Gateway 15.5 and earlier, plus Secure Email and Web Manager 15.5 and earlier
- Exploitation requires no credentials and no user interaction
- ZoomEye found 1,782 instances matching the Cisco Secure Email Gateway fingerprint
- CERT-In rated the advisory bundle CRITICAL in note CIVN-2026-0461
Read next
Security