What happened
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.
Affected versions
Cisco Secure Email: 14.0.0-698; 13.5.1-277; 13.0.0-392; 14.2.0-620; 13.0.5-007; 13.5.4-038; 14.2.1-020; 14.3.0-032; 15.0.0-104; 15.0.1-030; 15.5.0-048; 15.5.1-055; 15.5.2-018; 16.0.0-050; 15.0.3-002; 16.0.0-054; 15.5.3-022; 16.0.1-017; 15.5.4-012; 16.0.4-016; 15.0.5-016; 16.0.2-112; 16.0.3-044; 13.6.2-023; 13.6.2-078; 13.0.0-249; 13.0.0-277; 13.8.1-052; 13.8.1-068; 13.8.1-074; 14.0.0-404; 12.8.1-002; 14.1.0-227; 13.6.1-201; 14.2.0-203; 14.2.0-212; 12.8.1-021; 13.8.1-108; 14.2.0-224; 14.3.0-120; 15.0.0-334; 15.5.1-024; 15.5.1-029; 15.5.2-005; 16.0.0-195; 15.5.3-017; 16.0.1-010; 15.0.1-035; 16.0.2-088; 15.5.4-007; 15.0.2-007; 16.0.4-010; 16.0.3-016 Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.