Junglewise Threat Intelligence

CVE-2026-20355: Cisco Secure Email S/MIME ciphertext decryption vulnerability

CVE-2026-20355 · Severity: medium · CVSS 5.9 · Published 2026-09-02

Vendors: Cisco.

Executive brief

Cisco Secure Email is an enterprise gateway solution that protects email communications using encryption. These vulnerabilities in S/MIME decryption allow unauthenticated remote attackers to recover plaintext from encrypted emails through man-in-the-middle techniques, potentially exposing sensitive business communications. A successful exploit bypasses email encryption protections without requiring authentication or user interaction.

Technical details

These vulnerabilities stem from insufficient validation of S/MIME message integrity in Cisco Secure Email's decryption functionality (CWE-345: Insufficient Verification of Data Authenticity; CWE-354: Improper Validation of Extraneous Input). An unauthenticated remote attacker can exploit these flaws via man-in-the-middle techniques by intercepting and modifying traffic between email gateways when S/MIME is configured for inter-gateway communication. The attack vector is network-based, requires high complexity (CVSS AC:H), and no prior authentication or user interaction. A successful exploit allows plaintext recovery from encrypted emails. Fixes are available in updated AsyncOS releases beyond 16.5.0, and Cisco reports no workarounds.

Affected products

  • Cisco Secure Email AsyncOS Software Release 16.5.0 and earlier

Timeline

  • 2026-09-02: disclosed: Public disclosure by Cisco PSIRT
  • 2026-09-02: advisory: Cisco Security Advisory cisco-sa-esa-smime-disc-dzw4rEdY published

References

Related threats