Multiple security vulnerabilities have been identified in Cisco Secure Email's Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality, which could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity and can be exploited by intercepting and modifying traffic between email gateways. Affected devices run Cisco AsyncOS Software Release 16.5.0 or earlier with S/MIME configured for communication between email gateways.
CVE-2026-20354 (CVSS 5.9 — High): An unauthenticated, remote attacker could recover plain text from encrypted email messages by exploiting insufficient validation of message integrity in the S/MIME decryption functionality.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Cisco Secure Email's Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality, which could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity and can be exploited by intercepting and modifying traffic between email gateways. Affected devices run Cisco AsyncOS Software Release 16.5.0 or earlier with S/MIME configured for communication between email gateways.
CVE-2026-20354 (CVSS 5.9 — High): An unauthenticated, remote attacker could recover plain text from encrypted email messages by exploiting insufficient validation of message integrity in the S/MIME decryption functionality.[emaillocker id="1283"]
CVE-2026-20355: An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways, allowing them to obtain plaintext content from the encrypted communication.
These vulnerabilities collectively present a significant risk to organizations that use Cisco Secure Email for secure email communication.
We recommend you to update Cisco Secure Email to given version link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Secure/Multipurpose%20Internet%20Mail%20Extensions%20Ciphertext%20Decryption%20Vulnerabilities%26vs_k=1
The following reports contain further technical details: