# Cisco Secure Email Gateway RCE exploited

Published: 2026-01-18 · Severity: high
Canonical: https://vorant.io/reports/577fb5f0-84a1-5607-a92e-27805eb519a3/cisco-secure-email-gateway-rce-exploited

> A command execution flaw in Cisco Secure Email Gateway and Secure Email and Web Manager is being actively exploited by unauthenticated attackers to gain root.

The Japan IPA has issued an alert regarding CVE-2025-20393, a command execution vulnerability affecting Cisco Secure Email Gateway and Secure Email and Web Manager appliances. The flaw allows an unauthenticated remote attacker to execute arbitrary commands with root privileges, representing a full compromise of the affected security appliance.

Cisco has confirmed that exploitation of this vulnerability has been observed in the wild, and the vendor has released patched versions to address the issue. Given that these are email security gateways—often internet-facing and central to organizational mail flow—active exploitation poses a significant risk of further compromise. IPA recommends organizations apply the vendor-provided updates immediately following Cisco's published guidance.

## Mentioned in this report

- Vulnerabilities: CVE-2025-20393 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260119.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/577fb5f0-84a1-5607-a92e-27805eb519a3/cisco-secure-email-gateway-rce-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
