VORANT. Threat Intelligence Sign in Get the full feed

Cisco Email Gateway RCE exploited in wild

critical vulnerability

Cisco warns of active exploitation of CVE-2025-20393, a critical unauthenticated RCE in Secure Email Gateway allowing root-level command execution.

Japan's IPA has issued an advisory regarding CVE-2025-20393, a critical remote code execution vulnerability in Cisco Secure Email Gateway and Secure Email and Web Manager. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges on vulnerable appliances.

Cisco has confirmed active exploitation of this vulnerability in the wild. The security appliance vendor has released patches to address the issue and is urging customers to update immediately. Given the combination of unauthenticated access, root-level execution, and confirmed exploitation, this represents an urgent threat to organizations using affected Cisco email security products.

Organizations running Cisco Secure Email Gateway or Secure Email and Web Manager should prioritize patching according to the vendor's published guidance. The IPA advisory warns that the scope of attacks may expand, making immediate remediation critical for affected deployments.

Mentioned in this report

Vulnerabilities CVE-2025-20393KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260119.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free