Cisco patches five CVEs in Secure Email Gateway and Email and Web Manager
Cisco released a September patch for Secure Email Gateway and Secure Email and Web Manager 15.5 and later, fixing five CVEs ranging from path traversal to denial of service. CERT-In assigned the update critical status (CIVN-2026-0461).
- CVE-2026-76440 — unauthenticated path traversal bypassing directory restrictions
- CVE-2026-76441 — authentication and authorization bypass by remote attacker
- CVE-2026-76442 and CVE-2026-20353 lead to resource exhaustion and denial of service
- Affects Secure Email Gateway and Email and Web Manager versions 15.5 and later
Read next
Security