Cisco has issued a warning about two unpatched vulnerabilities in its Secure Email product that could allow attackers to intercept and modify encrypted email communications. The flaws, tracked as CVE-2026-20354 and CVE-2026-20355, affect the S/MIME decryption functionality of the threat protection solution and have been publicly disclosed. This means that anyone with knowledge of these vulnerabilities can exploit them, potentially compromising sensitive information.
The vulnerabilities are medium-severity issues that could allow an attacker to intercept traffic between email gateways using a man-in-the-middle (MitM) technique. In a worst-case scenario, this could enable the attacker to obtain plaintext content from encrypted communications. Cisco notes that all Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.
This is not an isolated issue – on the same day, Cisco also announced patches for critical-severity security defects in its IOS XR and Nexus 9000 series switches. These vulnerabilities could lead to remote code execution (RCE), authentication bypass, code injection, and other types of attacks. The fixes resolve multiple bugs grouped under seven CVEs, including two with a CVSS score of 9.8.
In addition to these patches, Cisco addressed a high-severity vulnerability in its Desk Phone, IP Phone, and Video Phone series devices running the Session Initiation Protocol (SIP). Tracked as CVE-2026-20281, this bug allows remote, unauthenticated attackers to send continuous streams of crafted HTTP packets to the vulnerable devices and cause a denial-of-service (DoS) condition.
While Cisco claims it is not aware of any of these vulnerabilities being exploited in the wild, the fact that they have been publicly disclosed means that anyone with malicious intent can use this information to launch attacks. This highlights the importance of keeping software up-to-date and patching vulnerabilities as soon as possible.
If you’re a Secure Email user, it’s essential to check your device’s version and update to the latest AsyncOS version if necessary. Additionally, be cautious when communicating sensitive information via email, especially with external parties. Remember that even encrypted emails can be vulnerable to interception if not properly secured.
As a general best practice, make sure to regularly review and update your security software, including email clients and network devices. This will help prevent potential exploits and minimize the risk of data breaches. Stay vigilant and stay informed – cybersecurity threats are constantly evolving, and it’s crucial to adapt and respond quickly to emerging risks.
Source: SecurityWeek — 2026-09-03