CVE-2026-20354
published 2026-09-02CVE-2026-20354: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an…
PriorityP335medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.16%
4.6th percentile
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain te
ghsa_unreviewed·2026-09-02
CVE-2026-20354 [MEDIUM] CWE-354 Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain te
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
VulDB
Cisco Secure Email up to 16.5.0-780 S/MIME Decryption missing encryption (EUVD-2026-70210)
vuldb·2026-09-02·CVSS 5.9
CVE-2026-20354 [MEDIUM] Cisco Secure Email up to 16.5.0-780 S/MIME Decryption missing encryption (EUVD-2026-70210)
A vulnerability described as problematic has been identified in Cisco Secure Email. This impacts an unknown function of the component S/MIME Decryption. Executing a manipulation can lead to missing encryption of sensitive data.
This vulnerability is tracked as CVE-2026-20354. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
2026-09-02
Published