Description
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.

These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
Published: 2026-09-02
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, classified as CWE‑354, arises from insufficient validation of message integrity in the S/MIME decryption functionality of Cisco Secure Email. An unauthenticated, remote attacker can exploit this flaw via a man‑in‑the‑middle approach to intercept and modify traffic between email gateways. Successful exploitation permits the attacker to recover plaintext from encrypted email communications, leading to a confidentiality breach.

Affected Systems

Cisco Secure Email is affected. No specific version information is provided, so all relevant deployments of Cisco Secure Email should be reviewed for the vulnerability.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The lack of an EPSS score suggests limited publicly known exploitation, but the attack requires an active man‑in‑the‑middle position and no authentication, making it potentially realistic in compromised network segments. The risk remains significant for confidentiality if the attacker can position themselves between email gateways.

Generated by OpenCVE AI on September 3, 2026 at 10:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Cisco Secure Email patch or upgrade as detailed in the Cisco Security Advisory to address the S/MIME decryption validation flaw.
  • Ensure all mail gateway-to-gateway connections use TLS with integrity protection to mitigate man‑in‑the‑middle tampering.
  • Segment the email traffic network and monitor for suspicious alterations to reduce the attacker’s ability to intercept and modify messages.

Generated by OpenCVE AI on September 3, 2026 at 10:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Email
Vendors & Products Cisco
Cisco secure Email

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
Title Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
Weaknesses CWE-354
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Cisco Secure Email
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-02T17:58:58.074Z

Reserved: 2025-10-08T11:59:15.414Z

Link: CVE-2026-20354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T17:17:33.897

Modified: 2026-09-02T19:23:13.660

Link: CVE-2026-20354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses
  • CWE-354

    Improper Validation of Integrity Check Value