Description
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.

These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
Published: 2026-09-02
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Multiple vulnerabilities in Cisco Secure Email’s S/MIME decryption allow an unauthenticated attacker to recover plaintext from encrypted messages. The weaknesses stem from insufficient validation of message integrity, enabling a man‑in‑the‑middle to modify traffic and force the system into decrypting tampered payloads. The result is a compromise of confidentiality, exposing the contents of supposedly protected communications.

Affected Systems

Affected systems include Cisco Secure Email. Version details are not specified; the vulnerability impacts the S/MIME decryption component used by the product.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, so current exploitation likelihood is uncertain. The described attack requires a network position that permits traffic interception, such as a compromised email gateway or insecure network segment, and relies on the attacker’s ability to alter encrypted messages before decryption occurs. This is an identified weakness in cryptographic protocol implementation per CWE-345.

Generated by OpenCVE AI on September 3, 2026 at 10:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Cisco Secure Email patches or upgrade to a version that resolves the S/MIME decryption weaknesses.
  • If a fix is not yet available, restrict or disable S/MIME functionality on mail gateways until the issue is remedied, and enforce transport‑level encryption such as TLS for mail transmission.
  • Continuously monitor mail logs for abnormal S/MIME decryption failures or evidence of message tampering, and review network segmentation to limit the ability of an attacker to perform a man‑in‑the‑middle.

Generated by OpenCVE AI on September 3, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco secure Email
Vendors & Products Cisco
Cisco secure Email

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.
Title Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Cisco Secure Email
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-02T17:58:57.899Z

Reserved: 2025-10-08T11:59:15.414Z

Link: CVE-2026-20355

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-02T17:17:34.027

Modified: 2026-09-02T19:23:13.660

Link: CVE-2026-20355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:30:05Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity