Back to list

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities — CISCO-SA-ESA-SMIME-DISC-DZW4REDY

Cisco · Cisco · CISCO-SA-ESA-SMIME-DISC-DZW4REDY

ID
CISCO-SA-ESA-SMIME-DISC-DZW4REDY
Date
Source
Cisco
Vendor
Cisco
Threat
medium

Summary

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept…

Timeline

Published by source
2026-09-02

Risk context

  • Reported severity or threat level: medium.
  • Review exposure for the affected product or family: Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption.

Product

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption

What to do

General, cautious steps (verify details in the official source):

  • Review exposure and plan remediation based on risk and environment.
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Evidence and provenance

Canonical advisory ID
CISCO-SA-ESA-SMIME-DISC-DZW4REDY
Source
Cisco
Vendor
Cisco
Published by source
2026-09-02
Last source activity
2026-09-02
Additional identifiers
CVE-2026-20354
Curated by
hlukh.ch

Related advisories and connections

These advisories are connected by shared CVE, product, vendor, source, or time signals.