Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution.
By Dillip Chowdary • Sep 03, 2026 • Source: SecurityWeek
What happened
Cisco has issued a dual set of security notifications, warning customers about unpatched vulnerabilities in its Secure Email gateway products while simultaneously delivering critical patches for its high-end switch operating systems. According to disclosures reported by SecurityWeek, the unpatched issues reside in how the email security system handles S/MIME, creating situations where attackers could expose encrypted email content. At the same time, Cisco addressed severe security flaws in its IOS XR and Nexus
Cisco on Wednesday warned that two unpatched vulnerabilities in its enterprise email security product Secure Email have been publicly disclosed. The two flaws, tracked as CVE-2026-20354 and CVE-2026-20355, are medium-severity issues affecting the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of the threat protection solution.
How it works

According to Cisco, insufficient validation of message integrity can allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique. “A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication,” Cisco says in its advisory, adding that all Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
Why it matters
Cisco warns that the security bugs have been publicly disclosed, but notes that it is not aware of any of them being exploited in the wild. See the full write-up from SecurityWeek via the source link for quotes and complete context.
Who is affected
Read the original coverage at SecurityWeek via the source link above for the complete details and primary quotes.
What to watch next
Cross-check release notes and official docs before changing production systems based on early reporting.
Developer Action Items
- ☐ Inventory whether iOS / Cisco runs in prod, CI, staging, or on laptops before you debate severity.
- ☐ Pull the vendor advisory for CVE-2026-20354, CVE-2026-20355 and patch from that page — not from a social recap.
- ☐ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- ☐ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Advertisement