Security Advisory Desk
mediumQCS priority 82/100Cisco

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Cisco Secure Email has security issues in its S/MIME email encryption feature. An attacker who is not logged in but can intercept communication between email servers could grab the original, readable content from encrypted emails. This happens because the system does not properly check if messages have been tampered with. There are no ways to work around this problem without updating the software.

Published 2/9/2026, 4:00:00 pmVerified 3/9/2026, 4:17:25 amRevision 1
Cisco medium network security advisory visual

In plain language

What this advisory means

Cisco Secure Email has security issues in its S/MIME email encryption feature. An attacker who is not logged in but can intercept communication between email servers could grab the original, readable content from encrypted emails. This happens because the system does not properly check if messages have been tampered with. There are no ways to work around this problem without updating the software.

Technical explanation

How the issue affects the environment

Multiple vulnerabilities exist in the S/MIME decryption function of Cisco Secure Email, due to insufficient validation of message integrity. These weaknesses allow an unauthenticated, remote attacker to exploit a man-in-the-middle (MITM) position between email gateways to intercept and modify encrypted email traffic. Successful exploitation results in recovery of plaintext from encrypted email messages. The affected platforms run Cisco AsyncOS Software Release 16.5.0 or earlier with S/MIME configured for gateway communication. No workarounds are available; remediation requires upgrading to fixed software releases.

Operational impact

Why teams should care

An attacker could gain unauthorized access to the content of encrypted emails, potentially exposing sensitive business information, confidential communications, or private data. This compromises confidentiality, risks intellectual property loss, regulatory non-compliance, and harms trust with partners and clients. No immediate workaround exists, so remediation through software upgrade is necessary to maintain secure email communications and protect business assets.

Immediate action

Cisco strongly recommends upgrading affected Cisco Secure Email devices running AsyncOS 16.5.0 or earlier to the fixed software releases indicated in the Cisco bug IDs CSCwu28362 and CSCwu28364 to eliminate these vulnerabilities. Users should contact Cisco TAC for assistance obtaining fixed software versions.

Affected and fixed releases

Affected versionsCisco AsyncOS 16.5.0 and earlier with S/MIME configured
Fixed versionsRefer to Cisco bug IDs CSCwu28362 and CSCwu28364 for fixed releases (not specified here)

Temporary risk reduction

There are no workarounds available for these vulnerabilities. Effective remediation requires applying the fixed software releases provided by Cisco.

Evidence and validation checklist

  • Cisco official security advisory dated September 2, 2026
  • Details on vulnerability mechanism and impact from Cisco PSIRT advisories
  • Explicit statement on lack of workarounds
  • Cisco CVE and bug tracking references CSCwu28362, CSCwu28364
  • Cisco PSIRT public advisory and security impact rating medium
  • No known exploitation reports per Cisco PSIRT

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source