DIRAS TAKE
Urgently treat this as high priority: the flaw allows unauthenticated remote code execution and the vendor has no fixed releases listed for these builds. Immediately reduce network exposure and follow the vendor's guidance while monitoring for signs of compromise.
What is CVE-2026-76443?
Remote attackers can execute arbitrary code on Cisco Secure Email appliances with no authentication or user interaction required; this vulnerability is tracked as CVE-2026-76443. Affected builds span Cisco Secure Email 13.x, 14.x and 15.x (examples include 13.0.0-392, 13.0.5-007, 13.5.1-277, 13.5.4-038, 14.0.0-698, 14.2.0-620, 14.2.1-020, 14.3.0-032, 15.0.0-104 and 15.0.1-030). An attacker only needs network access to vulnerable appliances to exploit this improper-neutralization flaw (CWE-707).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Cisco Cisco Secure Email are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Cisco Secure Email 14.x | 14.0.0-698 | |
| Cisco Secure Email 13.x | 13.5.1-277 | |
| Cisco Secure Email 13.x | 13.0.0-392 | |
| Cisco Secure Email 14.x | 14.2.0-620 | |
| Cisco Secure Email 13.x | 13.0.5-007 | |
| Cisco Secure Email 13.x | 13.5.4-038 | |
| Cisco Secure Email 14.x | 14.2.1-020 | |
| Cisco Secure Email 14.x | 14.3.0-032 | |
| Cisco Secure Email 15.x | 15.0.0-104 | |
| Cisco Secure Email 15.x | 15.0.1-030 |
Is CVE-2026-76443 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-76443
- Isolate or restrict network access to Cisco Secure Email appliances from untrusted networks and the internet.
- Apply any vendor guidance or mitigations Cisco publishes for CVE-2026-76443 as soon as available.
- Monitor appliance logs and network traffic for unusual activity and enable additional logging where possible.
- Plan for rapid patch testing and deployment once Cisco provides fixed builds for the affected 13.x, 14.x and 15.x releases.
Frequently asked questions
Is CVE-2026-76443 being actively exploited?
There are no public reports of exploitation of CVE-2026-76443 as of 2026-09-30.
Which Cisco Secure Email versions are affected by CVE-2026-76443?
Cisco Secure Email builds in 13.x, 14.x and 15.x are listed as affected, including specific builds such as 13.0.0-392, 13.0.5-007, 13.5.1-277, 13.5.4-038, 14.0.0-698, 14.2.0-620, 14.2.1-020, 14.3.0-032, 15.0.0-104 and 15.0.1-030.
Is there a patch for CVE-2026-76443?
No fixed builds are listed for CVE-2026-76443 in the affected data; follow Cisco's advisories for when patches are released.
Does CVE-2026-76443 require authentication?
No—this vulnerability permits unauthenticated remote code execution against Cisco Secure Email appliances given network access.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76443
- cve.org/CVERecord?id=CVE-2026-76443
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026