Cisco warns of S/MIME flaws, patches critical switch bugs

Cisco warned two publicly disclosed S/MIME flaws in Secure Email could let a man-in-the-middle reveal plaintext and released patches for IOS XR, Nexus 9000 and phone bugs.

On Wednesday Cisco warned that two publicly disclosed vulnerabilities in its Secure Email appliance could allow a man-in-the-middle attacker to obtain plaintext from encrypted messages, and the company released patches for multiple critical switch and phone flaws.

The Secure Email issues are tracked as CVE-2026-20354 and CVE-2026-20355. Cisco described them as medium-severity defects in the S/MIME decryption path of the product. Devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected. Cisco’s advisory warns that insufficient validation of message integrity can let an attacker positioned between email gateways intercept and modify encrypted traffic. “A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication,” the advisory states. Cisco reported the vulnerabilities have been publicly disclosed and said it is not aware of active exploitation.

Separately, Cisco published fixes for multiple high-severity and critical vulnerabilities in IOS XR and Nexus 9000 series switches that could lead to remote code execution, authentication bypass and memory corruption. The IOS XR updates address several grouped bugs under seven CVE identifiers, including CVE-2026-20274 and CVE-2026-20279, each rated 9.8 by CVSS and tied to memory corruption and improper access control. The Nexus 9000 fixes cover CVE-2026-20212, also rated 9.8, where remote attackers could connect to by-default open TCP ports and execute code with root privileges.

Cisco also closed a high-severity issue in IP and video desk phones that use the Session Initiation Protocol. Tracked as CVE-2026-20281, the bug affects Desk Phone 9800, IP Phone 7800 and 8800 series and Video Phone 8875 devices. The flaw can be triggered by unauthenticated attackers sending continuous streams of crafted HTTP packets, potentially causing a denial-of-service condition. Cisco said it has no reports of these patched vulnerabilities being exploited in the wild.

Cisco published advisories and software updates to address the issues and recommended that customers apply available patches. Administrators running Secure Email should verify their AsyncOS version and whether S/MIME is enabled and plan upgrades where necessary. Network operators using IOS XR and Nexus 9000 hardware should review the advisory to identify the fixed images and schedule updates, especially on devices reachable from untrusted networks.

The advisory notes basic mitigation steps such as restricting unnecessary exposure of management and TCP service ports and monitoring systems for unexpected behavior while updates are applied. S/MIME is a standard used to sign and encrypt email; on gateway devices S/MIME decryption is used to allow inspection of encrypted messages. A failure in message integrity checks can permit modified messages to be accepted by a gateway and reveal decrypted content.

Administrators can find detailed patch information, affected releases and recommended upgrade paths in Cisco’s published advisories and should follow those instructions when applying fixes.

Articles by this author