Executive brief
Cisco Secure Email is an enterprise gateway solution that protects email communications using encryption. These vulnerabilities in S/MIME decryption allow unauthenticated remote attackers to recover plaintext from encrypted emails through man-in-the-middle techniques, potentially exposing sensitive business communications. A successful exploit bypasses email encryption protections without requiring authentication or user interaction.
Technical details
These vulnerabilities stem from insufficient validation of S/MIME message integrity in Cisco Secure Email's decryption functionality (CWE-345: Insufficient Verification of Data Authenticity; CWE-354: Improper Validation of Extraneous Input). An unauthenticated remote attacker can exploit these flaws via man-in-the-middle techniques by intercepting and modifying traffic between email gateways when S/MIME is configured for inter-gateway communication. The attack vector is network-based, requires high complexity (CVSS AC:H), and no prior authentication or user interaction. A successful exploit allows plaintext recovery from encrypted emails. Fixes are available in updated AsyncOS releases beyond 16.5.0, and Cisco reports no workarounds.
Affected products
- Cisco Secure Email AsyncOS Software Release 16.5.0 and earlier
Timeline
- 2026-09-02: disclosed: Public disclosure by Cisco PSIRT
- 2026-09-02: advisory: Cisco Security Advisory cisco-sa-esa-smime-disc-dzw4rEdY published