Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Improper control of a resource during its lifecycle, enabling potential unauthorized operations
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper control of a resource throughout its lifetime, a flaw categorized under CWE-664. The flaw can allow a malicious actor to misuse the resource, potentially leading to unauthorized actions or escalation of privileges, as reflected by the CVSS score of 9.8.

Affected Systems

Cisco Secure Email Gateway devices are affected. Specific advisory, so all installations of Cisco Secure Email Gateway should be considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The high CVSS score indicates the vulnerability is severe; the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the gateway’s administrative or management interfaces, given the nature of the flaw and the environment in which Cisco Secure Email operates. While no exploitation data is supplied, the potential for remote exploitation exists based on the severity rating.

Generated by OpenCVE AI on September 20, 2026 at 23:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco Secure Email Gateway hardening release to all affected appliances.
  • Reconfigure the system to enforce strict initialization and cleanup of resources according to Cisco’s recommended settings.
  • Implement monitoring of resource usage and anomalies associated with improper control.

Generated by OpenCVE AI on September 20, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Email
Vendors & Products Cisco
Cisco secure Email

Tue, 15 Sep 2026 18:30:00 +0000


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Title Cisco Secure Email Gateway Security Hardening Release
Weaknesses CWE-664
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cisco Secure Email
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-15T17:03:57.940Z

Reserved: 2025-10-08T11:59:15.414Z

Link: CVE-2026-20353

cve-icon Vulnrichment

Updated: 2026-09-15T17:03:57.940Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T17:17:43.000

Modified: 2026-09-15T18:17:19.887

Link: CVE-2026-20353

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime