Cisco on Wednesday warned that two unpatched vulnerabilities in its enterprise email security product Secure Email have been publicly disclosed.
The two flaws, tracked as CVE-2026-20354 and CVE-2026-20355, are medium-severity issues affecting the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of the threat protection solution.
According to Cisco, insufficient validation of message integrity can allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique.
“A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication,” Cisco says in its advisory, adding that all Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are affected.
Cisco warns that the security bugs have been publicly disclosed, but notes that it is not aware of any of them being exploited in the wild.
On Wednesday, the tech giant also announced patches for multiple critical-severity security defects in IOS XR and Nexus 9000 series switches that could lead to remote code execution (RCE), authentication bypass, code injection, and other types of attacks.
The fixes for IOS XR resolve multiple bugs grouped based on their underlying vulnerability classes under seven CVEs, including two with a CVSS score of 9.8: CVE-2026-20274 and CVE-2026-20279. These include memory corruption and memory safety bugs and improper access control issues, respectively.
The Nexus 9000 series switches received fixes for CVE-2026-20212 (CVSS score of 9.8), a security weakness that allows remote attackers to connect to by-default accessible TCP ports and execute code with root privileges.
Additionally, Cisco addressed a high-severity vulnerability in Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 series devices running the Session Initiation Protocol (SIP).
Tracked as CVE-2026-20281, the bug allows remote, unauthenticated attackers to send continuous streams of crafted HTTP packets to the vulnerable devices and cause a denial-of-service (DoS) condition.
Cisco says it is not aware of any of the patched vulnerabilities being exploited in the wild. Additional information can be found on the company’s notification of advisory publication.
Related: Exploit Published for Fresh Cleo Harmony Vulnerability
Related: Chrome and Firefox Updates Patch Dozens of Vulnerabilities
Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
Related: Hackers Start Exploiting Critical Langflow Vulnerability
