Cisco Warns of Vulnerabilities in Secure Email Product
Cisco has issued a warning about two security vulnerabilities in its Secure Email product. The flaws, listed as CVE-2026-20354 and CVE-2026-20355, affect the S/MIME decryption function used to protect corporate emails. These issues are rated as moderate severity.
The core vulnerability is related to insufficient verification of message integrity during the S/MIME decryption process. In a possible attack scenario, a remote attacker could intercept and modify communication between email gateways, leading to a Man-in-the-Middle (MitM) attack.
Cisco says the vulnerabilities affect Secure Email devices running AsyncOS version 16.5.0 or earlier, provided that S/MIME is enabled. Although there have been no reported incidents of these vulnerabilities being used in actual attacks, their disclosure makes it crucial for organizations to respond promptly.