Cyber & AI intelligence
Wasteland.
Briefs indexed2606
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-20353 2026-09-14

CVE-2026-20353: Critical Resource-Lifecycle Flaw in Cisco Secure Email Products

"Cisco disclosed a CVSS 9.8 critical vulnerability class in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, found during an internal security review and fixed via software hardening releases."

Cisco disclosed a CVSS 9.8 critical vulnerability class in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, found during an internal security review and fixed via software hardening releases.

What Is It

CVE-2026-20353 covers a set of vulnerabilities identified by Cisco's own engineering team during a comprehensive internal security review of Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. The issues involve improper control of a resource through its lifetime, grouped under CWE-664 (a CWE Pillar-level weakness). Cisco's PSIRT is the CNA and assigned the identifier; the review produced hardening releases rather than a single point patch.

Why It Matters

The CVSS 3.1 base score is 9.8 (CRITICAL), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination is the worst-case profile: reachable over the network, low attack complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability. CISA's SSVC assessment scores the technical impact as total and marks the flaw automatable: yes, meaning an attacker could reliably script exploitation at scale.

The counterweight: CISA's SSVC entry records exploitation as none, and no CISA KEV entry was supplied for this CVE, there is no evidence in the source material of active exploitation in the wild. NVD status is "Awaiting Analysis" as of publication on 2026-09-14.

What's Vulnerable

Cisco Secure Email, across a wide span of release trains. Affected versions listed by Cisco include:

No CPE data has been published yet. Note that even the most recent 16.0.x builds appear on the affected list.

Patch Status

Cisco has published software hardening releases addressing these vulnerabilities. Administrators should consult the Cisco security advisory below for fixed-release mapping and upgrade to a hardened build. No workarounds or mitigations are documented in the supplied source material, and no KEV-mandated remediation deadline applies.

Sources