Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

Cisco found several security weaknesses in its Secure Email Gateway and Secure Email and Web Manager products during internal testing. One weakness is already being exploited by attackers. Cisco released software updates to fix these problems. There are no known workarounds, so users should update their software as soon as possible to stay safe.

Published 14/9/2026, 4:00:00 pmVerified 14/9/2026, 6:35:54 pmRevision 1
Cisco critical network security advisory visual

In plain language

What this advisory means

Cisco found several security weaknesses in its Secure Email Gateway and Secure Email and Web Manager products during internal testing. One weakness is already being exploited by attackers. Cisco released software updates to fix these problems. There are no known workarounds, so users should update their software as soon as possible to stay safe.

Technical explanation

How the issue affects the environment

A comprehensive internal security review of Cisco Secure Email Gateway and Secure Email and Web Manager revealed multiple vulnerabilities across different CWE classes, including path traversal (CWE-23), improper access control (CWE-284), resource control (CWE-664), injection flaws such as SQL injection (CWE-707), and improper input validation (CWE-1284). These issues allow unauthorized access, resource misuse, and code injection, potentially enabling remote attackers to compromise confidentiality, integrity, and availability. One SQL Injection vulnerability is known to be actively exploited. Cisco assigned CVE identifiers CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, and CVE-2026-76443 to these grouped vulnerabilities. Software updates fixing these issues were released, with no effective workarounds available.

Operational impact

Why teams should care

If exploited, these vulnerabilities could lead to unauthorized data access, service disruption, or control loss over Cisco Secure Email Gateway and Secure Email and Web Manager devices. This risk can harm the confidentiality and integrity of email communications and web management, impacting organizational security posture and potentially causing operational and reputational damage.

Immediate action

Cisco strongly recommends upgrading affected devices to fixed software releases listed above. Upgrades can be performed via the appliance's web-based system upgrade interface or command-line interface. Regularly consult Cisco advisories and coordinate with Cisco TAC for assistance if needed.

Affected and fixed releases

Affected versionsCisco Secure Email Gateway 15.5 and earlier, Cisco Secure Email and Web Manager 15.5 and earlier
Fixed versionsCisco Secure Email Gateway 15.5.5-014 and later, Cisco Secure Email Gateway 16.5.0-780 and later, Cisco Secure Email and Web Manager 15.5.5-006 and later, Cisco Secure Email and Web Manager 16.5.0-429 and later

Temporary risk reduction

There are no workarounds that mitigate these vulnerabilities. Prompt application of Cisco-provided updates is the only effective remediation.

Evidence and validation checklist

  • Internal security review uncovered vulnerabilities
  • Multiple CWE classes identified with assigned CVEs
  • Known active exploitation of one injection vulnerability
  • Cisco issued software hardening and published updates
  • Explicit statement that no workarounds exist
  • Release notes and fixed version listings provided

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source