Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
PatchCisco Secure EmailCisco IOS XROur summary
Cisco has issued security advisories addressing unpatched S/MIME decryption flaws in Secure Email, identified as CVE-2026-20354 and CVE-2026-20355, which expose users to man-in-the-middle attacks capable of revealing plaintext content. Simultaneously, the vendor deployed urgent patches for critical vulnerabilities in IOS XR and Nexus 9000 series switches, including high-severity defects like CVE-2026-20274 and CVE-2026-20212 that enable remote code execution and authentication bypass. While Cisco reports no active in-the-wild exploitation for these issues, the potential for severe compromise necessitates immediate attention for administrators managing affected network and mail infrastructure.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.