Cisco Releases Critical Fixes for Secure Email, IOS XR and Nexus 9000
Cisco published security advisories for Secure Email, IOS XR and Nexus 9000. Several vulnerabilities reach a CVSS score of 9.8; at the time of publication, the manufacturer had no evidence of malicious exploitation.

Cisco released fixes published on September 2, 2026, affect Secure Email gateways, the IOS XR network operating system and Nexus 9000 switches with Silicon One ASICs. The advisories include several vulnerabilities with a maximum CVSS score of 9.8. Cisco PSIRT said that, at the time the advisories were issued, it was not aware of malicious exploitation of the flaws in the affected products.
Cisco released fixes for Nexus 9000
According to the scope of impact, CVE-2026-20212 in Cisco Nexus 9000 switches with Silicon One ASICs is expected to have the highest priority. The vulnerability has a CVSS score of 9.8 and could allow a remote, unauthenticated attacker to execute code with root privileges.
Cisco released updated software. Until an organization deploys the update, the manufacturer also lists a temporary risk-reduction measure: access to TCP ports 43210 and 43211 can be filtered using an infrastructure ACL (iACL) or the Live Protect shield mechanism. This mitigation is relevant to operators of affected devices, but it is not a replacement for the update.
Secure Email: S/MIME risk between gateways
Two flaws, CVE-2026-20354 and CVE-2026-20355, affect S/MIME processing in Cisco Secure Email. In a man-in-the-middle attack between email gateways, they could allow an attacker to obtain the plaintext of encrypted communications.
Systems running AsyncOS 16.5.0 and earlier are affected if S/MIME is enabled for communication between gateways. The attack requires a position between the communicating gateways and the relevant S/MIME configuration.
Cisco does not list a workaround for these two flaws. It recommends upgrading to a fixed software release; the specific fixed versions are listed in the details of the relevant Cisco bug IDs.
Seven flaws in IOS XR
Cisco also released hardening updates for seven CVEs in IOS XR. These include CVE-2026-20274 and CVE-2026-20279, both with a maximum CVSS score of 9.8. The advisory applies to all IOS XR releases, including IOS XR7 (LNT).
Cisco does not list a workaround for the IOS XR vulnerabilities. Operators should therefore review the versions in use and plan deployment of the relevant SMU software fixes or an upgrade according to the supported branch.
What to check in the infrastructure
- for Nexus 9000, verify whether the device uses a Silicon One ASIC and consider restricting TCP ports 43210 and 43211 before updating;
- for Cisco Secure Email, check the AsyncOS version and whether S/MIME is active for communication between email gateways;
- for IOS XR, identify the branch in use, including IOS XR7 (LNT), and available SMUs or fixed releases;
- monitor new information from Cisco and independent researchers about any potential active exploitation.
Cisco does not list known malicious exploitation of the Secure Email, IOS XR or Nexus 9000 flaws in the advisories.
Sources
- Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities – Confirms the scope, attack conditions, absence of a workaround, update recommendation and known-exploitation status for CVE-2026-20354 and CVE-2026-20355.
- Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability – Confirms CVE-2026-20212, CVSS 9.8, the possibility of RCE with root privileges, affected devices, fixes, workaround and the absence of known exploitation.
- Cisco IOS XR Software Security Hardening Release: September 2026 – Confirms seven CVEs in IOS XR, the scope covering all releases, the maximum score of 9.8, corrective SMUs and the absence of a workaround or known exploitation.
- Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities – Independently summarizes Cisco’s September advisories and their affected products.
Verified and updated: 09/03/2026 13:35


