Improper validation of integrity check value in Secure Email Gateway - CVE-2026-20355
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insufficient validation of message integrity in the S/MIME decryption functionality when processing intercepted and modified traffic between email gateways. A remote attacker can use a machine-in-the-middle technique to intercept and modify traffic to disclose sensitive information.
Only deployments with S/MIME configured for communication between email gateways are vulnerable.