๐Ÿ” CVE Alert

CVE-2026-20354

MEDIUM 5.9

Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

CWE CWE-354
Vendor cisco
Product cisco secure email
Ecosystems
Industries
NetworkingTelecommunications
Published Sep 2, 2026
Last Updated Sep 2, 2026
Stay Ahead of the Next One

Get instant alerts for cisco cisco secure email

Be the first to know when new medium vulnerabilities affecting cisco cisco secure email are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Cisco / Cisco Secure Email
14.0.0-698 13.5.1-277 13.0.0-392 14.2.0-620 13.0.5-007 13.5.4-038 14.2.1-020 14.3.0-032 15.0.0-104 15.0.1-030 15.5.0-048 15.5.1-055 15.5.2-018 16.0.0-050 15.0.3-002 16.0.0-054 15.5.3-022 16.0.1-017 15.5.4-012 16.0.4-016 15.0.5-016 16.0.2-112 16.0.3-044 16.5.0-780

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sec.cloudapps.cisco.com: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY