VORANT. Threat Intelligence Sign in Get the full feed

Cisco Secure Email Gateway RCE exploited

high vulnerability

A command execution flaw in Cisco Secure Email Gateway and Secure Email and Web Manager is being actively exploited by unauthenticated attackers to gain root.

The Japan IPA has issued an alert regarding CVE-2025-20393, a command execution vulnerability affecting Cisco Secure Email Gateway and Secure Email and Web Manager appliances. The flaw allows an unauthenticated remote attacker to execute arbitrary commands with root privileges, representing a full compromise of the affected security appliance.

Cisco has confirmed that exploitation of this vulnerability has been observed in the wild, and the vendor has released patched versions to address the issue. Given that these are email security gateways—often internet-facing and central to organizational mail flow—active exploitation poses a significant risk of further compromise. IPA recommends organizations apply the vendor-provided updates immediately following Cisco's published guidance.

Mentioned in this report

Vulnerabilities CVE-2025-20393KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260119.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free