CVE-2026-20354
Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
| CWE | CWE-354 |
| Vendor | cisco |
| Product | cisco secure email |
| Ecosystems | |
| Industries | NetworkingTelecommunications |
| Published | Sep 2, 2026 |
| Last Updated | Sep 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for cisco cisco secure email
Be the first to know when new medium vulnerabilities affecting cisco cisco secure email are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Cisco / Cisco Secure Email
14.0.0-698 13.5.1-277 13.0.0-392 14.2.0-620 13.0.5-007 13.5.4-038 14.2.1-020 14.3.0-032 15.0.0-104 15.0.1-030 15.5.0-048 15.5.1-055 15.5.2-018 16.0.0-050 15.0.3-002 16.0.0-054 15.5.3-022 16.0.1-017 15.5.4-012 16.0.4-016 15.0.5-016 16.0.2-112 16.0.3-044 16.5.0-780