CVE-2026-20353: pre-auth remote compromise in Cisco Cisco Secure Email

An unauthenticated remote attacker with network access to Cisco Secure Email can exploit CVE-2026-20353 to take control of the appliance. The issue is a resource lifetime management bug (CWE-664) that may allow full compromise of the product. Cisco lists multiple affected builds across 13.x, 14.x and 15.x branches, including 13.0.0-392, 13.5.1-277, 13.0.5-007, 13.5.4-038, 14.0.0-698, 14.2.0-620, 14.2.1-020, 14.3.0-032, 15.0.0-104 and 15.0.1-030. Exploitation requires only network reachability; no authentication or user interaction is needed.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00396
CWE
CWE-664
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: because this can be triggered without credentials and reachable services increase risk, immediately restrict external access to Cisco Secure Email and prepare to apply vendor updates when available.

What is CVE-2026-20353?

An unauthenticated remote attacker with network access to Cisco Secure Email can exploit CVE-2026-20353 to take control of the appliance. The issue is a resource lifetime management bug (CWE-664) that may allow full compromise of the product. Cisco lists multiple affected builds across 13.x, 14.x and 15.x branches, including 13.0.0-392, 13.5.1-277, 13.0.5-007, 13.5.4-038, 14.0.0-698, 14.2.0-620, 14.2.1-020, 14.3.0-032, 15.0.0-104 and 15.0.1-030. Exploitation requires only network reachability; no authentication or user interaction is needed.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Cisco Cisco Secure Email are affected?

BRANCHAFFECTEDFIXED
14.x14.0.0-698
13.x13.5.1-277
13.x13.0.0-392
14.x14.2.0-620
13.x13.0.5-007
13.x13.5.4-038
14.x14.2.1-020
14.x14.3.0-032
15.x15.0.0-104
15.x15.0.1-030

Is CVE-2026-20353 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-20353

  1. Restrict network exposure: block or limit access to Cisco Secure Email interfaces from untrusted networks.
  2. Apply network controls: enforce firewall rules, require VPN or bastion access, and use IP allowlists for management and service ports.
  3. Increase monitoring: review logs and alert on anomalous activity, crashes, or unexpected process restarts on Secure Email appliances.
  4. Follow Cisco guidance and deploy vendor hardening releases or patches as soon as Cisco publishes them.

Frequently asked questions

Is CVE-2026-20353 being actively exploited?

There are no public reports of active exploitation of CVE-2026-20353 as of 2026-09-30.

Which Cisco Secure Email versions are affected by CVE-2026-20353?

Multiple builds in the 13.x, 14.x and 15.x branches are affected; Cisco listed affected builds including 13.0.0-392, 13.5.1-277, 13.0.5-007, 13.5.4-038, 14.0.0-698, 14.2.0-620, 14.2.1-020, 14.3.0-032, 15.0.0-104 and 15.0.1-030.

Is there a patch for CVE-2026-20353?

As of 2026-09-30 there is no vendor-listed fix; monitor Cisco advisories for published hardening releases or patches.

Does CVE-2026-20353 require authentication?

No; Cisco notes the vulnerability can be triggered remotely without authentication or user interaction against Cisco Secure Email.

References