CVE-2026-20353 PUBLISHED

Cisco Secure Email Gateway Security Hardening Release

Assigner: cisco
Reserved: 08.10.2025 Published: 14.09.2026 Updated: 15.09.2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Cisco
Product Cisco Secure Email
Versions Default: unknown
  • Version 14.0.0-698 is affected
  • Version 13.5.1-277 is affected
  • Version 13.0.0-392 is affected
  • Version 14.2.0-620 is affected
  • Version 13.0.5-007 is affected
  • Version 13.5.4-038 is affected
  • Version 14.2.1-020 is affected
  • Version 14.3.0-032 is affected
  • Version 15.0.0-104 is affected
  • Version 15.0.1-030 is affected
  • Version 15.5.0-048 is affected
  • Version 15.5.1-055 is affected
  • Version 15.5.2-018 is affected
  • Version 16.0.0-050 is affected
  • Version 15.0.3-002 is affected
  • Version 16.0.0-054 is affected
  • Version 15.5.3-022 is affected
  • Version 16.0.1-017 is affected
  • Version 15.5.4-012 is affected
  • Version 16.0.4-016 is affected
  • Version 15.0.5-016 is affected
  • Version 16.0.2-112 is affected
  • Version 16.0.3-044 is affected

Exploits

Except as otherwise noted previously, the Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.

References

Problem Types

  • Improper Control of a Resource Through its Lifetime cwe