DIRAS TAKE
Urgent: treat this as high priority because the flaw allows unauthenticated remote access and no fixes are listed; immediately reduce internet exposure and follow vendor advisories for mitigations.
What is CVE-2026-76441?
Remote, unauthenticated attackers can bypass access controls and gain complete control over Cisco Secure Email and Web Manager, tracked as CVE-2026-76441. The flaw stems from improper access control (CWE-284) and affects multiple builds across 12.x, 13.x and 14.x branches (examples include 12.8.1-002, several 13.0 and 13.6 builds, and 14.0/14.1 builds listed by Cisco). Exploitation requires only network access to the product; no user interaction or valid credentials are required according to the vulnerability data and CVSS vector.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Cisco Cisco Secure Email and Web Manager are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 13.x | 13.6.2-023 | |
| 13.x | 13.6.2-078 | |
| 13.x | 13.0.0-249 | |
| 13.x | 13.0.0-277 | |
| 13.x | 13.8.1-052 | |
| 13.x | 13.8.1-068 | |
| 13.x | 13.8.1-074 | |
| 14.x | 14.0.0-404 | |
| 12.x | 12.8.1-002 | |
| 14.x | 14.1.0-227 |
Is CVE-2026-76441 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-76441
- Isolate affected appliances from untrusted networks and remove direct internet access where feasible.
- Apply network-level restrictions: firewall rules, ACLs, and allowlisting to limit management interfaces to trusted hosts.
- Enable and increase monitoring and logging of the product for unusual authentication bypass, configuration changes, or administrative actions.
- Subscribe to Cisco advisories and implement vendor guidance or patches as soon as Cisco releases fixes; contact Cisco support for timelines and recommended mitigations.
Frequently asked questions
Is CVE-2026-76441 being actively exploited?
There are no public reports of exploitation of CVE-2026-76441 as of 2026-09-30.
Which Cisco Secure Email and Web Manager versions are affected by CVE-2026-76441?
Multiple builds across Cisco Secure Email and Web Manager 12.x, 13.x and 14.x are listed as affected; the vendor lists specific affected builds such as 12.8.1-002, several 13.0 and 13.6 builds, and 14.0/14.1 builds in its advisory data.
Is there a patch for CVE-2026-76441?
No fixed versions are listed for CVE-2026-76441 in the provided data; the vendor has not published a patch as of 2026-09-30.
Does CVE-2026-76441 require authentication?
No: the vulnerability allows bypassing access controls without valid credentials, so Cisco Secure Email and Web Manager can be impacted by unauthenticated network access.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76441
- cve.org/CVERecord?id=CVE-2026-76441
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026