CVE-2026-20353
Received
Received - Intake
Improper Resource Control in Cisco Secure Email Gateway
Vulnerability report for CVE-2026-20353, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-14
Last updated on: 2026-09-14
Assigner: Cisco Systems, Inc.
Description
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cisco | secure_email_gateway | * |
| cisco | secure_email_and_web_manager | * |
| cisco | secure_email_gateway | 15.5.5-014 |
| cisco | secure_email_and_web_manager | 15.5.5-006 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-664 | The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release. |