Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco Alerts on Unpatched Email Flaws, Critical Switch Patches

Cisco Alerts on Unpatched Email Flaws, Critical Switch Patches

Posted on September 3, 2026 By CWS

Cisco has issued a warning regarding two security flaws in its Secure Email product, which have not yet been patched. These vulnerabilities, made public on Wednesday, impact the S/MIME decryption process within the email security solution.

Details of the Email Vulnerabilities

The flaws, identified as CVE-2026-20354 and CVE-2026-20355, are of medium severity and involve inadequate validation of message integrity. Attackers could exploit these vulnerabilities by employing a man-in-the-middle (MitM) method to intercept and alter communications between email gateways.

Cisco’s advisory states that a successful exploit could result in attackers accessing plaintext information from encrypted emails. The affected systems include all Secure Email devices operating on AsyncOS version 16.5.0 or earlier with S/MIME enabled. Despite the public disclosure, there is no evidence of these vulnerabilities being used in active attacks.

Critical Patches for Network Devices

In addition to the email vulnerabilities, Cisco also released patches for critical security issues in its IOS XR and Nexus 9000 series switches. These vulnerabilities could potentially lead to remote code execution, authentication bypass, and other serious attacks.

The IOS XR updates address several vulnerabilities, categorized under seven different CVEs, with two rated at a CVSS score of 9.8 (CVE-2026-20274 and CVE-2026-20279). These fixes include resolving memory corruption and improper access control problems.

For the Nexus 9000 series, a fix was provided for CVE-2026-20212, also with a CVSS score of 9.8, which permits remote attackers to exploit default TCP ports and execute code with high-level privileges.

Additional Security Updates

Cisco also addressed a significant vulnerability in several of its communication devices, such as Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 series. This high-severity issue, identified as CVE-2026-20281, could enable attackers to initiate a denial-of-service (DoS) attack by sending continuous streams of malicious HTTP packets to these devices.

Cisco has confirmed that none of these patched vulnerabilities have been reported as exploited in real-world scenarios. More information can be found in their official security advisory publication.

As these vulnerabilities present considerable risks, organizations using Cisco products are advised to apply the recommended updates promptly to safeguard their systems against potential threats.

Security Week News Tags:Cisco, critical flaws, email security, IOS XR, network security, Nexus 9000, Patches, S/MIME, Security, Vulnerabilities

Post navigation

Previous Post: Microsoft Enhances Windows Security with Memory Integrity
Next Post: Critical HP Easy Start Vulnerabilities on macOS Exposed

Related Posts

Qualcomm Flags Exploitation of Adreno GPU Flaws, Urges OEMs to Patch Urgently Qualcomm Flags Exploitation of Adreno GPU Flaws, Urges OEMs to Patch Urgently Security Week News
Data Integrity Crisis: Trusting Information in AI Era Data Integrity Crisis: Trusting Information in AI Era Security Week News
Cyera Raises 0 Million at  Billion Valuation Cyera Raises $400 Million at $9 Billion Valuation Security Week News
Zero-Day Flaw in TrueConf Exploited by Hackers Zero-Day Flaw in TrueConf Exploited by Hackers Security Week News
Chip Programming Firm Data I/O Hit by Ransomware Chip Programming Firm Data I/O Hit by Ransomware Security Week News
Bonfy.AI Raises .5 Million for Adaptive Content Security Platform Bonfy.AI Raises $9.5 Million for Adaptive Content Security Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web
  • Hackers Exploit QR Codes in Phishing Scams
  • Claude AI Outage Disrupts Key Models and Services
  • Avast Antivirus Vulnerability Exposed by Chaotic Eclipse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web
  • Hackers Exploit QR Codes in Phishing Scams
  • Claude AI Outage Disrupts Key Models and Services
  • Avast Antivirus Vulnerability Exposed by Chaotic Eclipse

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark