CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-20354

criticalCVSS 5.9covered by 4 sourcesfirst seen 2026-09-02
A remote, anonymous attacker can exploit multiple vulnerabilities in Cisco AsyncOS and Cisco Secure Email Gateway to bypass security measures.

CSIRTS triage

What
Multiple vulnerabilities in Cisco Secure Email Gateway and AsyncOS allow remote anonymous attackers to bypass security measures.
Who is affected
Deployments of Cisco Secure Email Gateway handling email traffic.
Urgency
Medium severity; security bypass requires prompt patching to prevent unauthorized access.
Action
Apply patches for CVE-2026-20354 and CVE-2026-20355 to Cisco Secure Email Gateway.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-20354

Get an email if CVE-2026-20354 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2026-20354

CVE.org record

Embed the live status

CVE-2026-20354 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-20354 status](https://www.csirts.com/badge/CVE-2026-20354)](https://www.csirts.com/cve/CVE-2026-20354)