Executive brief
Cisco Secure Email devices are vulnerable to attacks that could decrypt encrypted emails passing through email gateways. An attacker positioned between gateways can intercept and modify encrypted messages to extract plaintext content, compromising the confidentiality of encrypted communications without needing any authentication credentials.
Technical details
Multiple vulnerabilities in the S/MIME decryption functionality of Cisco Secure Email stem from insufficient validation of message integrity (CWE-345, CWE-354). An unauthenticated attacker using a machine-in-the-middle (MITM) technique can intercept and modify encrypted traffic between email gateways to recover plaintext from encrypted email messages. The vulnerability requires network access to the communication channel between gateways and S/MIME must be configured for gateway-to-gateway communication. The attack does not require user interaction or authentication. Cisco AsyncOS Software Release 16.5.0 and earlier versions are affected; fixed releases are available.
Affected products
- Cisco Secure Email AsyncOS Software Release 16.5.0 and earlier
Timeline
- 2026-09-02: disclosed
- 2026-09-08: advisory: Advisory version 1.1 published