Security Advisory Desk
mediumQCS priority 82/100Cisco

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Cisco Secure Email has weaknesses in its email encryption feature that could let hackers intercept and read encrypted emails without needing to log in. The issue happens because the system doesn't properly check if encrypted messages have been tampered with. Attackers could do this by positioning themselves between email servers and changing the messages as they pass through. There is currently no temporary fix, so users should update their software when a fixed version is available.

Published 8/9/2026, 11:22:17 amVerified 9/9/2026, 3:21:32 amRevision 2
Cisco medium network security advisory visual

In plain language

What this advisory means

Cisco Secure Email has weaknesses in its email encryption feature that could let hackers intercept and read encrypted emails without needing to log in. The issue happens because the system doesn't properly check if encrypted messages have been tampered with. Attackers could do this by positioning themselves between email servers and changing the messages as they pass through. There is currently no temporary fix, so users should update their software when a fixed version is available.

Technical explanation

How the issue affects the environment

The vulnerabilities affect the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption process in Cisco Secure Email devices running AsyncOS 16.5.0 or earlier with S/MIME communication configured between email gateways. The root cause is insufficient validation of message integrity during decryption, allowing an unauthenticated remote attacker to exploit a man-in-the-middle position to intercept and modify encrypted traffic between email gateways. This can lead to disclosure of plaintext from encrypted communications. There are no available workarounds; remediation requires upgrading to fixed software releases specified by Cisco.

Operational impact

Why teams should care

Exploitation allows unauthorized parties to access sensitive plaintext data transmitted in encrypted email communications, undermining confidentiality guarantees essential for corporate privacy and compliance. The medium severity reflects the potential exposure of confidential information, risking data breaches, loss of trust, regulatory penalties, and operational impact due to compromised communications.

Immediate action

Cisco strongly recommends upgrading Cisco Secure Email devices to fixed software releases addressing these vulnerabilities. Customers should contact Cisco TAC or authorized channels for access to fixed versions and ensure hardware compatibility before upgrading.

Affected and fixed releases

Affected versionsCisco AsyncOS Software Release 16.5.0 or earlier with S/MIME configured
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

There are no workarounds available for these vulnerabilities as per the official Cisco advisory.

Evidence and validation checklist

  • Cisco official security advisory from Cisco PSIRT dated 2026-09-08
  • Advisory states vulnerabilities in S/MIME decryption functionality of Cisco Secure Email
  • Detailed explanation of insufficient message integrity validation as root cause
  • Description of attack scenario involving man-in-the-middle interception between email gateways
  • Explicit statement that no workarounds are available
  • Recommendation to upgrade to fixed software releases
  • Public disclosure exists; no known exploits detected

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source