Executive Summary

    On September 14th, 2026, Cisco published a security hardening release for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, disclosing five vulnerabilities its own engineering team found during an internal security review. The most severe of these, tracked as CVE-2026-76443, allows an unauthenticated remote attacker to send crafted input that the appliance executes rather than treats as data. The remaining four are part of the same disclosure rather than steps in a single exploit chain. They all allow attackers to access internal information that can be leveraged to gain control of Cisco Secure Email instances. Cisco states that all five vulnerabilities affect the products regardless of device configuration. 

    Secure Email Gateway and Secure Email and Web Manager sit at the network edge and process inbound and outbound mail for the organizations that deploy them, which puts every message and the appliance's management plane within reach of anyone who compromises one. Cisco confirmed that one vulnerability belonging to the same improper neutralization class as CVE-2026-76443, tracked separately as CVE-2026-76461, is under active exploitation and was added to CISA's Known Exploited Vulnerabilities catalog on September 14th. Cisco patched a maximum-severity AsyncOS flaw in these same appliances in January 2026 after it was exploited as a zero-day beginning in November 2025. 

    Cisco reports no evidence that any of the five vulnerabilities in this hardening release have been exploited, and no public proof-of-concept code is known for them. Given that attackers are already operating against this appliance family and that a single upgrade remediates all five alongside the exploited flaw, Beazley Security recommends affected organizations apply available fixes immediately and conduct a thorough review for any signs of compromise. 

    Affected Systems or Products

    All five vulnerabilities affect the same products and releases. Cisco confirms they do not affect Cisco Secure Web Appliance.

    Product

    Affected Versions

    Fixed Version

    Cisco Secure Email Gateway

    15.5

    16.0

    16.5

    15.5.5-014 (No fix released or planned)

    16.5.0-780

    Cisco Secure Email and Web Manager

    15.5

    16.0

    16.5

    15.5.5-006

    (No fix released or planned)

    16.5.0-429

    Release 16.0 did not receive a fix. Migrate those devices directly to a fixed release.

    Mitigations / Workarounds

    Cisco states there are no workarounds for these vulnerabilities. Upgrading is the only remediation, and a single upgrade to a fixed release addresses all five vulnerabilities. 

    Upgrade over the network through the web-based management interface: 

    1. 1.

      Choose System Administration > System Upgrade. 

    2. 2.

      Click Upgrade Options. 

    3. 3.

      Click Download and Install. 

    4. 4.

      Choose a fixed release from the table above. 

    5. 5.

      Select the appropriate options in the Upgrade Preparation area. 

    6. 6.

      Click Proceed. The device reboots when the upgrade completes. 

    Administrators who prefer the CLI can run upgrade, enter DOWNLOADINSTALL, choose a fixed release, and work through the remaining prompts. The device will reboot once the upgrade completes. 

    Where operationally possible, restrict administrative access to these appliances to trusted internal networks while the upgrade is scheduled. 

    Patches

    Cisco has released fixed software for both affected products, and customers must apply it themselves. Version details and the full vulnerability breakdown are available in the official Cisco advisory.

    Technical Details

    Cisco disclosed these five vulnerabilities differently than a typical advisory, and the difference matters when reading them. Rather than assigning one identifier per flaw, Cisco grouped the issues by their underlying Common Weakness Enumeration class and assigned a single CVE to each grouping. Each identifier represents a set of related defects, not a single bug. Cisco says it took this approach to streamline patching and disclosure. 

    The practical consequence is that Cisco has not published technical details per issue. They have provided no affected endpoints, no root cause, and no reproduction path for any of the five. What is known is the class and the reachability. All five are remotely reachable without authentication, and Cisco states they apply regardless of device configuration, so there is no feature to disable or setting to check that takes a device out of scope. 

    CVE-2026-76443 is the most critical of these groupings to prioritize remediation. It covers improper neutralization, which includes both command injection and SQL injection, and it is the same weakness class as CVE-2026-76461, which Cisco has already confirmed is under active exploitation. That flaw is tracked and patched separately. Nothing published thus far indicates that the issues grouped under CVE-2026-76443 are reachable by the same code path, but they share a class with a defect that attackers have already proven they can reach. 

    How Beazley Security is responding

    Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

    We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

    If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.