Security News

Cisco Flags Unpatched Email Encryption Flaws, Rushes Fixes for Critical Switch Bugs

Security Week · 3 Sept 2026
Key Takeaway Ask your IT provider whether any Cisco network equipment or S/MIME-based email encryption you use is affected, and apply available patches immediately.

Cisco has issued security advisories covering two separate sets of issues. The first involves publicly disclosed flaws in S/MIME, the protocol many organisations rely on to encrypt sensitive email communications. These vulnerabilities remain unpatched, meaning attackers who exploit them could potentially expose the contents of encrypted emails that businesses assume are secure.

Separately, Cisco has released patches for critical vulnerabilities affecting its IOS XR software and Nexus switches, widely used in enterprise and service provider networks. These flaws could allow an attacker to remotely execute code on affected devices or bypass authentication controls entirely, potentially giving them a foothold to move deeper into a network. Because switches and routers sit at the core of network infrastructure, successful exploitation could have serious consequences for connectivity, data integrity, and downstream security controls.

While many small businesses don't run Cisco's enterprise-grade switching hardware directly, those that use managed IT providers, or that rely on S/MIME for encrypted email, should check with their vendors or IT teams about exposure. Cisco has released patches for the switch vulnerabilities, but a fix for the S/MIME issue was not yet available at the time of disclosure.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.