Executive brief
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager contain multiple critical vulnerabilities in resource management and access control discovered during an internal security review. These flaws could allow remote attackers to gain unauthorized access, manipulate files, or consume resources without authentication, potentially leading to service disruption, data theft, or system compromise. One vulnerability in this category is known to be actively exploited in the wild.
Technical details
The vulnerabilities grouped under CVE-2026-20353 involve improper control of resources through their lifetime (CWE-664), including issues with uncontrolled resource consumption, deserialization, and improper resource initialization. Additional hardening releases address related vulnerability classes including path traversal (CWE-23), access control bypass (CWE-284), injection attacks (CWE-707), and input validation flaws (CWE-1284). These are network-reachable services with no authentication required for exploitation (CVSS 9.8, AV:N/AC:L/PR:N/UI:N). Cisco has released fixed software versions: Secure Email Gateway 15.5.5-014 and 16.5.0-780; Secure Email and Web Manager 15.5.5-006 and 16.5.0-429. No workarounds are available.
Affected products
- Cisco Secure Email Gateway 15.5 and earlier, 16.0, 16.5
- Cisco Secure Email and Web Manager 15.5 and earlier, 16.0, 16.5
Timeline
- 2026-09-14: disclosed
- exploited: One vulnerability in this grouping (related to SQL injection) is known to be actively exploited
- 2026-09-14: patched: Fixed releases available: ESG 15.5.5-014, 16.5.0-780; ESWM 15.5.5-006, 16.5.0-429