ZeroHour

CVE-2026-20353

moderate

Critical Unauthenticated Flaws in Cisco Secure Email Gateway & Email/Web Manager

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-20353 bundles multiple internally discovered vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, grouped under the CWE-664 pillar ('improper control of a resource through its lifetime'). Cisco has not published technical detail on the individual flaws, but the maximum CVSS 3.1 score of 9.8 (network vector, low complexity, no privileges or user interaction required) indicates that at least one of the grouped issues is remotely exploitable without authentication with high impact on confidentiality, integrity, and availability. Successful exploitation could allow an unauthenticated attacker to fully compromise an affected email gateway or management appliance, which sit in a privileged position on the mail path and hold quarantine stores, message logs, and configuration data. The flaws were found through Cisco's proactive internal review and are addressed in software hardening releases rather than in response to observed attacks. No public proof-of-concept exists and the CVE is not in the CISA Known Exploited Vulnerabilities catalog as of this writing.

What to do: Upgrade Cisco Secure Email Gateway and Secure Email and Web Manager to the fixed software releases listed in the Cisco PSIRT advisory for CVE-2026-20353 — the fixed versions are not enumerated in the summary data, so verify against Cisco's advisory directly. Restrict management and web interface access to trusted internal networks or VPN, since these appliances are commonly exposed at the network edge. Review logs for anomalous behavior on the management interface and confirm quarantine data and configuration integrity after patching.

Affected
Cisco Secure Email Gateway (formerly Email Security Appliance / ESA)
Cisco Secure Email and Web Manager (formerly Security Management Appliance / SMA)
Estimated exposure
moderateon the order of thousands to low tens of thousands of internet-reachable appliances, with a larger population deployed internally (clearly an estimate) — Cisco ESA/SMA-style appliances are enterprise edge devices, and historical internet scan data (Shodan/Censys) has typically shown thousands to low tens of thousands of Cisco email security web interfaces exposed, though exact counts for…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

Weakness
CWE-664
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco patches actively exploited Secure Email Gateway zero-day CVE-2026-76461 enabling unauthenticated root command execution; CISA adds it to KEV.

Cisco disclosed that a critical zero-day (CVE-2026-76461) in the email parsing logic of AsyncOS for Secure Email Gateway is being actively exploited, allowing unauthenticated remote attackers to execute arbitrary SQL statements that lead to root-level command execution on virtual and physical appliances. CISA added the flaw to its KEV catalog and ordered federal agencies to patch within three days, by September 17. Cisco also patched four other critical SEG/SEWM vulnerabilities (CVE-2026-76440, CVE-2026-76441, CVE-2026-20353, CVE-2026-76443) with no evidence of exploitation, and shared IOCs including suspicious SQL statements in mail_logs.