CVE-2026-76441: pre-auth improper access control in Cisco Cisco Secure Email and Web Manager

Remote, unauthenticated attackers can bypass access controls and gain complete control over Cisco Secure Email and Web Manager, tracked as CVE-2026-76441. The flaw stems from improper access control (CWE-284) and affects multiple builds across 12.x, 13.x and 14.x branches (examples include 12.8.1-002, several 13.0 and 13.6 builds, and 14.0/14.1 builds listed by Cisco). Exploitation requires only network access to the product; no user interaction or valid credentials are required according to the vulnerability data and CVSS vector.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00533
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: treat this as high priority because the flaw allows unauthenticated remote access and no fixes are listed; immediately reduce internet exposure and follow vendor advisories for mitigations.

What is CVE-2026-76441?

Remote, unauthenticated attackers can bypass access controls and gain complete control over Cisco Secure Email and Web Manager, tracked as CVE-2026-76441. The flaw stems from improper access control (CWE-284) and affects multiple builds across 12.x, 13.x and 14.x branches (examples include 12.8.1-002, several 13.0 and 13.6 builds, and 14.0/14.1 builds listed by Cisco). Exploitation requires only network access to the product; no user interaction or valid credentials are required according to the vulnerability data and CVSS vector.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Cisco Cisco Secure Email and Web Manager are affected?

BRANCHAFFECTEDFIXED
13.x13.6.2-023
13.x13.6.2-078
13.x13.0.0-249
13.x13.0.0-277
13.x13.8.1-052
13.x13.8.1-068
13.x13.8.1-074
14.x14.0.0-404
12.x12.8.1-002
14.x14.1.0-227

Is CVE-2026-76441 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-76441

  1. Isolate affected appliances from untrusted networks and remove direct internet access where feasible.
  2. Apply network-level restrictions: firewall rules, ACLs, and allowlisting to limit management interfaces to trusted hosts.
  3. Enable and increase monitoring and logging of the product for unusual authentication bypass, configuration changes, or administrative actions.
  4. Subscribe to Cisco advisories and implement vendor guidance or patches as soon as Cisco releases fixes; contact Cisco support for timelines and recommended mitigations.

Frequently asked questions

Is CVE-2026-76441 being actively exploited?

There are no public reports of exploitation of CVE-2026-76441 as of 2026-09-30.

Which Cisco Secure Email and Web Manager versions are affected by CVE-2026-76441?

Multiple builds across Cisco Secure Email and Web Manager 12.x, 13.x and 14.x are listed as affected; the vendor lists specific affected builds such as 12.8.1-002, several 13.0 and 13.6 builds, and 14.0/14.1 builds in its advisory data.

Is there a patch for CVE-2026-76441?

No fixed versions are listed for CVE-2026-76441 in the provided data; the vendor has not published a patch as of 2026-09-30.

Does CVE-2026-76441 require authentication?

No: the vulnerability allows bypassing access controls without valid credentials, so Cisco Secure Email and Web Manager can be impacted by unauthenticated network access.

References