Cisco has issued a warning regarding two security flaws in its Secure Email product, which have not yet been patched. These vulnerabilities, made public on Wednesday, impact the S/MIME decryption process within the email security solution.
Details of the Email Vulnerabilities
The flaws, identified as CVE-2026-20354 and CVE-2026-20355, are of medium severity and involve inadequate validation of message integrity. Attackers could exploit these vulnerabilities by employing a man-in-the-middle (MitM) method to intercept and alter communications between email gateways.
Cisco’s advisory states that a successful exploit could result in attackers accessing plaintext information from encrypted emails. The affected systems include all Secure Email devices operating on AsyncOS version 16.5.0 or earlier with S/MIME enabled. Despite the public disclosure, there is no evidence of these vulnerabilities being used in active attacks.
Critical Patches for Network Devices
In addition to the email vulnerabilities, Cisco also released patches for critical security issues in its IOS XR and Nexus 9000 series switches. These vulnerabilities could potentially lead to remote code execution, authentication bypass, and other serious attacks.
The IOS XR updates address several vulnerabilities, categorized under seven different CVEs, with two rated at a CVSS score of 9.8 (CVE-2026-20274 and CVE-2026-20279). These fixes include resolving memory corruption and improper access control problems.
For the Nexus 9000 series, a fix was provided for CVE-2026-20212, also with a CVSS score of 9.8, which permits remote attackers to exploit default TCP ports and execute code with high-level privileges.
Additional Security Updates
Cisco also addressed a significant vulnerability in several of its communication devices, such as Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 series. This high-severity issue, identified as CVE-2026-20281, could enable attackers to initiate a denial-of-service (DoS) attack by sending continuous streams of malicious HTTP packets to these devices.
Cisco has confirmed that none of these patched vulnerabilities have been reported as exploited in real-world scenarios. More information can be found in their official security advisory publication.
As these vulnerabilities present considerable risks, organizations using Cisco products are advised to apply the recommended updates promptly to safeguard their systems against potential threats.
