CVE Tools

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

SecurityWeekBy Ionut Arghire

PatchCisco Secure EmailCisco IOS XR

Our summary

Cisco has issued security advisories addressing unpatched S/MIME decryption flaws in Secure Email, identified as CVE-2026-20354 and CVE-2026-20355, which expose users to man-in-the-middle attacks capable of revealing plaintext content. Simultaneously, the vendor deployed urgent patches for critical vulnerabilities in IOS XR and Nexus 9000 series switches, including high-severity defects like CVE-2026-20274 and CVE-2026-20212 that enable remote code execution and authentication bypass. While Cisco reports no active in-the-wild exploitation for these issues, the potential for severe compromise necessitates immediate attention for administrators managing affected network and mail infrastructure.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store