S/MIME Decryption Vulnerabilities in Cisco Secure Email
CVE-2026-20355
5.9MEDIUM
What is CVE-2026-20355?
Cisco Secure Email contains multiple vulnerabilities in its Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality. These flaws originate from inadequate validation of message integrity, allowing an unauthenticated, remote attacker to exploit them using a machine-in-the-middle approach. By intercepting and manipulating traffic between email gateways, an attacker could potentially retrieve plaintext from encrypted email messages, thereby compromising the confidentiality of sensitive communications.
Affected Version(s)
Cisco Secure Email 14.0.0-698
Cisco Secure Email 13.5.1-277
Cisco Secure Email 13.0.0-392