news.mlab.sh
Back to the feed
vulnerability

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

CriticalCVSS 9.8
Summary

Cisco has issued warnings and patches for several security vulnerabilities affecting its Secure Email product and network switch lines. Two S/MIME decryption flaws in Secure Email, alongside critical vulnerabilities in IOS XR and Nexus 9000 switches, could allow attackers to intercept communications, execute code, and cause denial-of-service attacks. Cisco states it’s not currently aware of active exploitation.

Cisco has issued warnings and patches for several security vulnerabilities affecting its Secure Email product and network switch lines. Two S/MIME decryption flaws in Secure Email, tracked as CVE-2026-20354 and CVE-2026-20355, could allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique, potentially obtaining plaintext content. According to Cisco, these are medium-severity issues affecting devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled.

Cisco also announced patches for multiple critical-severity security defects in IOS XR and Nexus 9000 series switches. These fixes address vulnerabilities that could lead to remote code execution (RCE), authentication bypass, code injection, and other types of attacks. The IOS XR fixes resolve multiple bugs grouped under seven CVEs, including two with a CVSS score of 9.8: CVE-2026-20274 (memory corruption) and CVE-2026-20279 (memory safety bugs). The Nexus 9000 series switches received a fix for CVE-2026-20212 (CVSS score of 9.8), a security weakness allowing remote attackers to connect to by-default accessible TCP ports and execute code with root privileges.

Furthermore, Cisco addressed a high-severity vulnerability in Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 series devices running the Session Initiation Protocol (SIP). Tracked as CVE-2026-20281, this bug allows remote, unauthenticated attackers to send continuous streams of crafted HTTP packets, causing a denial-of-service (DoS) condition.

Cisco states that it is not currently aware of any of the patched vulnerabilities being exploited in the wild. Additional information can be found on the company’s notification of advisory publication.

Read the full article at SecurityWeek