Vulnerability
Published 2026-09-02
Verified 2026-09-19

Cisco: unpatched Secure Email S/MIME flaws (CVE-2026-20354/20355); critical IOS XR and Nexus 9000 patches

SecurityWeek (3 September 2026) summarises Cisco’s 2 September advisory drop. Two medium-severity, publicly disclosed but unpatched issues in Secure Email S/MIME decryption — CVE-2026-20354 and CVE-2026-20355 — can let a MitM attacker obtain plaintext from encrypted gateway traffic; Cisco says all Secure Email devices on AsyncOS 16.5.0 or earlier with S/MIME enabled are affected and it is not aware of in-the-wild exploitation. The same day Cisco also shipped critical fixes for IOS XR (including CVE-2026-20274 and CVE-2026-20279 at CVSS 9.8 for memory-corruption / improper access-control classes) and Nexus 9000 series switches (CVE-2026-20212, CVSS 9.8: remote code execution with root via by-default accessible TCP ports), plus high-severity SIP phone DoS CVE-2026-20281 on Desk Phone 9800 / IP Phone 7800/8800 / Video Phone 8875. Primary vendor notice: cisco-sa-esa-smime-disc-dzw4rEdY and the 2 Sep publication notice. Apply available IOS XR / Nexus / phone patches; for Secure Email, follow Cisco’s advisory for workarounds until a fixed AsyncOS build ships.

Product
Cisco Secure Email (AsyncOS); IOS XR; Nexus 9000; Desk/IP/Video Phone SIP series
Versions
Secure Email AsyncOS 16.5.0 or earlier with S/MIME enabled (unpatched); IOS XR / Nexus 9000 / phones — see Cisco notice for fixed releases
CVSS
CVE-2026-20274/20279/20212 vendor CVSS 9.8; Secure Email pair medium (CVE-2026-20354/20355); phone DoS CVE-2026-20281 high — per SecurityWeek citing Cisco
Exploited in Australia?
no
Patch to
Apply Cisco IOS XR / Nexus 9000 / phone fixed releases from 2 Sep notice; Secure Email — workaround per cisco-sa-esa-smime until AsyncOS fix

Primary: Cisco SA: Secure Email S/MIME (CVE-2026-20354/20355) · Vendor: Cisco 2 Sep 2026 advisory publication notice · CVE: CVE-2026-20354, CVE-2026-20355, CVE-2026-20274, CVE-2026-20279, CVE-2026-20212, CVE-2026-20281 · WA SOC 20260904001 (4 Sep 2026; Nexus CVE-2026-20212 CVSS 9.8)

vulnerabilities network australia