Cisco Warns of Secure Email Flaws, Patches Critical Switch Vulnerabilities
Cisco has issued warnings about two unpatched vulnerabilities in its enterprise email security product Secure Email. The flaws, tracked as CVE-2026-20354 and CVE-2026-20355, affect the S/MIME decryption functionality of the threat protection solution and allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique.
A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication, Cisco says in its advisory. All Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.
Cisco warns that the security bugs have been publicly disclosed but notes it is not aware of any being exploited in the wild.