Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Cisco on Wednesday warned that two unpatched vulnerabilities in its enterprise email security product Secure Email have been publicly disclosed.
The two flaws, tracked as CVE-2026-20354 and CVE-2026-20355, are medium-severity issues affecting the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of the threat protection solution.
According to Cisco, insufficient validation of message integrity can allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique.
“A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication,” Cisco says in its advisory, adding that all Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.
Cisco warns that the security bugs have been publicly disclosed, but notes that it is not aware of any of them being exploited in the wild.
On Wednesday, the tech giant also announced patches for multiple critical-severity security defects in IOS...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE