Cisco added two publicly disclosed S/MIME decryption flaws in Secure Email and separate critical IOS XR and Nexus bugs to the same advisory, and it says none are known to be exploited. The Secure Email issues affect AsyncOS 16.5.0 or earlier with S/MIME enabled.
Cisco says the mail flaw comes from weak message-integrity checks: an attacker who can sit between gateways and tamper with the encrypted traffic can make the recipient accept and open it as plaintext. The IOS XR and Nexus fixes cover defects that can lead to remote code execution or authentication bypass, so the same advisory now spans both message confidentiality and device control.
If Secure Email is carrying S/MIME traffic, the trust boundary is not just the endpoint mailbox; it includes the gateway path in between. If IOS XR or Nexus 9000 gear sits on core or service-provider paths, the patch problem is no longer one product family at a time, and the remaining exposure is whatever devices still carry the affected releases.