Cisco Email Gateway Patch Fixes Five CVEs, Including Subtle DoS Flaw
Cisco's September 2026 hardening release for its email security appliances addresses five vulnerabilities, tracked under advisory cisco-sa-hardening-esa-dfCrfXkm. Among them, CVE-2026-20353 is a resource lifetime control flaw that can cause excessive resource consumption, service degradation, and system unresponsiveness through improper memory or handle management. CERT-In rated the full set of CVEs as CRITICAL under bulletin CIVN-2026-0461, published on 17 September 2026. Affected products include Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, both version 15.5 and earlier, across physical and virtual deployments. Administrators are advised to verify the exact build against the Cisco advisory and apply the specified fixed release, as the flaw could halt mail flow entirely for organisations routing all inbound email through the appliance.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in