DIRAS TAKE
Treat this as urgent: the flaw is unauthenticated and remotely reachable (CVSS 9.8). Immediately reduce external exposure, follow Cisco's guidance, and prepare to apply vendor fixes as soon as they are released.
What is CVE-2026-76440?
An unauthenticated remote attacker can exploit a path traversal flaw in Cisco Secure Email to access or overwrite files on affected appliances; this issue is tracked as CVE-2026-76440. The vendor lists multiple affected builds across Cisco Secure Email 13.x, 14.x and 15.x (for example 13.0.0-392, 13.5.1-277, 14.0.0-698, 14.2.1-020 and 15.0.1-030 among others). Exploitation requires network access to the product and does not require valid credentials or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Cisco Cisco Secure Email are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Cisco Secure Email 14.x | 14.0.0-698 | |
| Cisco Secure Email 13.x | 13.5.1-277 | |
| Cisco Secure Email 13.x | 13.0.0-392 | |
| Cisco Secure Email 14.x | 14.2.0-620 | |
| Cisco Secure Email 13.x | 13.0.5-007 | |
| Cisco Secure Email 13.x | 13.5.4-038 | |
| Cisco Secure Email 14.x | 14.2.1-020 | |
| Cisco Secure Email 14.x | 14.3.0-032 | |
| Cisco Secure Email 15.x | 15.0.0-104 | |
| Cisco Secure Email 15.x | 15.0.1-030 |
Is CVE-2026-76440 being exploited?
There are no public reports of active exploitation as of 2026-09-30; this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public exploit code is available.
How to fix CVE-2026-76440
- Follow Cisco's published guidance and advisories for Secure Email as they become available.
- Restrict network access to Secure Email appliances—block internet-facing management and administrative ports and limit access to trusted management networks.
- Increase logging and monitor appliance logs and file-system activity for signs of unexpected file access or modification.
- Prepare a rapid patching plan so you can install vendor fixes immediately when Cisco releases updates.
Frequently asked questions
Is CVE-2026-76440 being actively exploited?
There are no public reports of exploitation as of 2026-09-30; it is not listed in CISA's Known Exploited Vulnerabilities catalog and no public exploit code has been published.
Which Cisco Secure Email versions are affected by CVE-2026-76440?
Cisco lists multiple affected builds across Secure Email 13.x, 14.x and 15.x; the vendor's advisory enumerates specific builds such as 13.0.0-392, 13.5.1-277, 14.0.0-698, 14.2.1-020 and 15.0.1-030.
Is there a patch for CVE-2026-76440?
As of 2026-09-30 Cisco has not published a fixed release for the builds listed; follow Cisco's advisories for patch availability.
Does CVE-2026-76440 require authentication?
No; the vulnerability can be triggered remotely without valid credentials against network-accessible Cisco Secure Email appliances.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76440
- cve.org/CVERecord?id=CVE-2026-76440
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026