VYPR
patchPublished Sep 3, 2026· 1 source

Cisco Addresses Critical Switch Flaws, Warns of Unpatched Secure Email Vulnerabilities

Cisco has released patches for critical vulnerabilities in its IOS XR and Nexus network devices, while also issuing a warning about unpatched flaws in its Secure Email offering.

Cisco has alerted users to two unpatched vulnerabilities affecting its Secure Email product, specifically related to the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality. These medium-severity flaws, tracked as CVE-2026-20354 and CVE-2026-20355, could allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique. A successful exploit could result in the attacker obtaining plaintext content from encrypted communications.

According to Cisco's advisory, all Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are susceptible. While the vendor notes that these vulnerabilities have been publicly disclosed, it is not aware of any active exploitation in the wild. Users are strongly advised to monitor Cisco's advisories for future updates and potential patches.

In parallel, Cisco has also rolled out patches for several critical-severity vulnerabilities impacting its IOS XR and Nexus 9000 series switches. These vulnerabilities pose significant risks, potentially leading to remote code execution (RCE), authentication bypass, and code injection attacks. The timely application of these patches is crucial for network infrastructure security.

Among the fixes for IOS XR, two vulnerabilities stand out with a CVSS score of 9.8: CVE-2026-20274 and CVE-2026-20279. These defects are categorized under memory corruption, memory safety bugs, and improper access control issues, highlighting the diverse nature of the threats addressed.

The Nexus 9000 series switches are also affected by a critical vulnerability, CVE-2026-20212, which carries a CVSS score of 9.8. This flaw allows remote attackers to connect to by-default accessible TCP ports and execute code with root privileges, representing a severe security risk for network devices.

Furthermore, Cisco has addressed a high-severity denial-of-service (DoS) vulnerability in its Desk Phone 9800, IP Phone 7800, and 8800 series devices, as well as Video Phone 8875 series devices running Session Initiation Protocol (SIP). Tracked as CVE-2026-20281, this bug allows remote, unauthenticated attackers to cause a DoS condition by sending continuous streams of crafted HTTP packets.

Cisco has stated that it is not aware of any of the patched vulnerabilities in the switch and phone products being exploited in the wild. However, the vendor urges customers to apply the available updates as soon as possible to protect their networks and devices from potential compromise. Further technical details and specific version information can be found in Cisco's official security advisories.

Synthesized by Vypr AI