In plain language
What this advisory means
Cisco Secure Email has security issues in its S/MIME email encryption feature. An attacker who is not logged in but can intercept communication between email servers could grab the original, readable content from encrypted emails. This happens because the system does not properly check if messages have been tampered with. There are no ways to work around this problem without updating the software.
Technical explanation
How the issue affects the environment
Multiple vulnerabilities exist in the S/MIME decryption function of Cisco Secure Email, due to insufficient validation of message integrity. These weaknesses allow an unauthenticated, remote attacker to exploit a man-in-the-middle (MITM) position between email gateways to intercept and modify encrypted email traffic. Successful exploitation results in recovery of plaintext from encrypted email messages. The affected platforms run Cisco AsyncOS Software Release 16.5.0 or earlier with S/MIME configured for gateway communication. No workarounds are available; remediation requires upgrading to fixed software releases.
Operational impact
Why teams should care
An attacker could gain unauthorized access to the content of encrypted emails, potentially exposing sensitive business information, confidential communications, or private data. This compromises confidentiality, risks intellectual property loss, regulatory non-compliance, and harms trust with partners and clients. No immediate workaround exists, so remediation through software upgrade is necessary to maintain secure email communications and protect business assets.
Immediate action
Cisco strongly recommends upgrading affected Cisco Secure Email devices running AsyncOS 16.5.0 or earlier to the fixed software releases indicated in the Cisco bug IDs CSCwu28362 and CSCwu28364 to eliminate these vulnerabilities. Users should contact Cisco TAC for assistance obtaining fixed software versions.
Affected and fixed releases
Temporary risk reduction
There are no workarounds available for these vulnerabilities. Effective remediation requires applying the fixed software releases provided by Cisco.
Evidence and validation checklist
- Cisco official security advisory dated September 2, 2026
- Details on vulnerability mechanism and impact from Cisco PSIRT advisories
- Explicit statement on lack of workarounds
- Cisco CVE and bug tracking references CSCwu28362, CSCwu28364
- Cisco PSIRT public advisory and security impact rating medium
- No known exploitation reports per Cisco PSIRT
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
