CiscoCVE-2026-20353
As part of Cisco's ongoing commitment to proactive security and product quality
Critical9.8CVE-2026-20353 · Published Sep 14, 2026 · updated Sep 15, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco Secure Email Product | <= 14.0.0-698 | No fix yet |
| <= 13.5.1-277 | No fix yet | |
| <= 13.0.0-392 | No fix yet | |
| <= 14.2.0-620 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-664
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Cisco Identity Services Engine Software: remote code execution | Critical9.9 | No fix yet |
| Sep 14 | Cisco Secure Email: remote code execution | Critical9.8 | No fix yet |
| Sep 14 | Cisco Secure Email: path traversal | Critical9.8 | No fix yet |
| Sep 14 | Cisco Secure Email and Web Manager: improper access control | Critical9.8 | No fix yet |
| Sep 14 | Cisco Secure Email: improper quantity validation | High7.5 | No fix yet |
| Sep 14 | As part of Cisco's ongoing commitment to proactive security and product quality | Critical9.8 | No fix yet |