Home / Blog / Cisco Warns of Unpatched Secure Email Flaws, Patches…
Tech News

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch

Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution.

By Dillip Chowdary • Sep 03, 2026 • Source: SecurityWeek

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch

What happened

Cisco has issued a dual set of security notifications, warning customers about unpatched vulnerabilities in its Secure Email gateway products while simultaneously delivering critical patches for its high-end switch operating systems. According to disclosures reported by SecurityWeek, the unpatched issues reside in how the email security system handles S/MIME, creating situations where attackers could expose encrypted email content. At the same time, Cisco addressed severe security flaws in its IOS XR and Nexus

Cisco on Wednesday warned that two unpatched vulnerabilities in its enterprise email security product Secure Email have been publicly disclosed. The two flaws, tracked as CVE-2026-20354 and CVE-2026-20355, are medium-severity issues affecting the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of the threat protection solution.

How it works

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch
Illustration · Pexels

According to Cisco, insufficient validation of message integrity can allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique. “A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication,” Cisco says in its advisory, adding that all Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

Why it matters

Cisco warns that the security bugs have been publicly disclosed, but notes that it is not aware of any of them being exploited in the wild. See the full write-up from SecurityWeek via the source link for quotes and complete context.

Who is affected

Read the original coverage at SecurityWeek via the source link above for the complete details and primary quotes.

What to watch next

Cross-check release notes and official docs before changing production systems based on early reporting.

Developer Action Items

  • Inventory whether iOS / Cisco runs in prod, CI, staging, or on laptops before you debate severity.
  • Pull the vendor advisory for CVE-2026-20354, CVE-2026-20355 and patch from that page — not from a social recap.
  • If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
  • Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →