For anyone reading this in the future, there are two possible causes for this.
1. You are using a static list of CAs that need to be manually maintained instead of a McAfee Maintained List for the Default Known CAs -- see McAfee KnowledgeBase - How to create a McAfee maintained known Certificate Authority list
2. A problem in MWG continuing to download updates from a CRL which has been removed from the configuration. See below.
The root of the second issue was that while the CRL was removed from our Default Known CAs (McAfee Subscribed list), the update process did not forget it, so it kept downloading the file (this is as Andre mentioned ). This is why you get the error over and over.
A reboot or restart of mwg services (service mwg restart) will fix this problem -- allowing the update process to rebuild its list of CRLs that need to be downloaded. This is also fixed in 188.8.131.52 and 7.5.1 -- meaning MWG will stop downloading from CRLs that don't exist in the configuration.
Web Gateway 184.108.40.206 Release Notes - https://kc.mcafee.com/corporate/index?page=content&id=PD25711
Web Gateway 7.5.1 Release Notes - https://kc.mcafee.com/corporate/index?page=content&id=PD25710
Release notes entry:
A certificate revocation list that had been removed was still in use on Web Gateway and produced error messages when certificates from this list were processed. (1027981)