TL;DR
Cisco published advisories for several product flaws on September 2, 2026. A public announcement already exists for the Cisco Secure Email vulnerability pair, CVE-2026-20354 and CVE-2026-20355. These S/MIME flaws let an attacker recover plaintext from encrypted email. A separate phone flaw, CVE-2026-20281, allows denial of service. No malicious use has been confirmed for any of them.
- Product: Cisco (2 products)
- Vulnerabilities: 3 flaws (CVE-2026-20354, CVE-2026-20355, CVE-2026-20281)
- Highest severity: 7.5 (High · CVSSv3)
- Worst impact: Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-20281 | 7.5 | CWE-401 | Not exploited |
| CVE-2026-20354 | 5.9 | CWE-354 | Not exploited |
| CVE-2026-20355 | 5.9 | CWE-345 | Not exploited |
Why It Matters
S/MIME exists to keep email content private. Therefore, a decryption flaw undercuts a core trust control. This Cisco Secure Email vulnerability could expose sensitive message contents.
The phone flaw affects widely deployed desk and IP phones. As a result, an attacker could knock devices offline. Together, the advisories touch both messaging and voice infrastructure.
How the Email Attack Works
Both S/MIME issues stem from weak integrity checks. The advisory says they exist “due to insufficient validation of message integrity”. An attacker uses a machine-in-the-middle position between email gateways.
From there, the attacker intercepts and modifies traffic. A successful exploit could “obtain plaintext content from the encrypted communication”. Each flaw scores 5.9 CVSS. This report withholds exploit detail.
How the Phone Attack Works
CVE-2026-20281 is a memory-management bug in Cisco SIP Software. The advisory notes it triggers when a device “processes HTTP packets”. An attacker sends a continuous stream of crafted packets.
Consequently, the phone consumes memory until it fails. A manual reboot is then required. The flaw scores 7.5 CVSS.
Exploitation Status
For the S/MIME flaws, Cisco confirms a public announcement is available. However, its PSIRT is not aware of any malicious use. For the phone flaw, Cisco reports no public announcements and no exploitation. No public proof-of-concept code has been confirmed for any of the three.
Affected Products
The email flaws affect Cisco Secure Email with S/MIME decryption enabled. The phone flaw affects Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 running SIP Software. The phone must be registered to Unified CM with Web Access enabled.
Patch and Mitigation Steps
No workarounds fix the S/MIME flaws, so upgrading is required. Review the Cisco Secure Email S/MIME advisory for fixed releases. For the phones, disabling Web Access mitigates the risk. Full steps appear in the Cisco phone DoS advisory. Still, patching remains the durable fix.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!