CiscoCVE-2026-20354
Cisco Secure Email: unauthenticated, remote attacker could recover plain text
Medium5.9CVE-2026-20354 · Published Sep 2, 2026
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cisco Secure Email Product | <= 14.0.0-698 | No fix yet |
| <= 13.5.1-277 | No fix yet | |
| <= 13.0.0-392 | No fix yet | |
| <= 14.2.0-620 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-354
More Cisco advisories
All Cisco| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 2 | Cisco Secure Email: insufficient authenticity check | Medium5.9 | No fix yet |
| Sep 2 | Cisco IOS XR Software: protection mechanism failure | High8.2 | No fix yet |
| Sep 2 | As part of Cisco's ongoing commitment to proactive security and product quality | High8.8 | No fix yet |
| Sep 2 | Cisco IOS XR Software: improper access control | Critical9.8 | No fix yet |
| Sep 2 | Cisco IOS XR Software: unhandled exceptional condition | High8.8 | No fix yet |
| Sep 2 | Cisco Session Initiation Protocol (SIP) Software: denial of service | High7.5 | No fix yet |