Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass.

Cisco patches

Cisco on Wednesday warned that two unpatched vulnerabilities in its enterprise email security product Secure Email have been publicly disclosed.

The two flaws, tracked as CVE-2026-20354 and CVE-2026-20355, are medium-severity issues affecting the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of the threat protection solution.

According to Cisco, insufficient validation of message integrity can allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique.

“A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication,” Cisco says in its advisory, adding that all Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.

Cisco warns that the security bugs have been publicly disclosed, but notes that it is not aware of any of them being exploited in the wild.

On Wednesday, the tech giant also announced patches for multiple critical-severity security defects in IOS XR and Nexus 9000 series switches that could lead to remote code execution (RCE), authentication bypass, code injection, and other types of attacks.

Advertisement. Scroll to continue reading.

The fixes for IOS XR resolve multiple bugs grouped based on their underlying vulnerability classes under seven CVEs, including two with a CVSS score of 9.8: CVE-2026-20274 and CVE-2026-20279. These include memory corruption and memory safety bugs and improper access control issues, respectively.

The Nexus 9000 series switches received fixes for CVE-2026-20212 (CVSS score of 9.8), a security weakness that allows remote attackers to connect to by-default accessible TCP ports and execute code with root privileges.

Additionally, Cisco addressed a high-severity vulnerability in Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 series devices running the Session Initiation Protocol (SIP).

Tracked as CVE-2026-20281, the bug allows remote, unauthenticated attackers to send continuous streams of crafted HTTP packets to the vulnerable devices and cause a denial-of-service (DoS) condition.

Cisco says it is not aware of any of the patched vulnerabilities being exploited in the wild. Additional information can be found on the company’s notification of advisory publication.

Related: Exploit Published for Fresh Cleo Harmony Vulnerability

Related: Chrome and Firefox Updates Patch Dozens of Vulnerabilities

Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

Related: Hackers Start Exploiting Critical Langflow Vulnerability

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Tom Bonos has been named Chief Revenue Officer at Sumo Logic.

Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.

Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.