# Cisco Email Gateway RCE exploited in wild

Published: 2026-01-18 · Severity: critical
Canonical: https://vorant.io/reports/577fb5f0-84a1-5607-a92e-27805eb519a3/cisco-email-gateway-rce-exploited-in-wild

> Cisco warns of active exploitation of CVE-2025-20393, a critical unauthenticated RCE in Secure Email Gateway allowing root-level command execution.

Japan's IPA has issued an advisory regarding CVE-2025-20393, a critical remote code execution vulnerability in Cisco Secure Email Gateway and Secure Email and Web Manager. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges on vulnerable appliances.

Cisco has confirmed active exploitation of this vulnerability in the wild. The security appliance vendor has released patches to address the issue and is urging customers to update immediately. Given the combination of unauthenticated access, root-level execution, and confirmed exploitation, this represents an urgent threat to organizations using affected Cisco email security products.

Organizations running Cisco Secure Email Gateway or Secure Email and Web Manager should prioritize patching according to the vendor's published guidance. The IPA advisory warns that the scope of attacks may expand, making immediate remediation critical for affected deployments.

## Mentioned in this report

- Vulnerabilities: CVE-2025-20393 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260119.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/577fb5f0-84a1-5607-a92e-27805eb519a3/cisco-email-gateway-rce-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
