# Cisco Secure Email Gateway and Secure Email and Web Manager contain actively exploited…

Published: 2026-01-18 · Severity: critical
Canonical: https://vorant.io/reports/8f680c1f-ef1d-403a-9f69-24e4415d343e/cisco-secure-email-gateway-and-secure-email-and-web-manager-contain-actively

> Cisco Secure Email Gateway and Secure Email and Web Manager contain actively exploited unauthenticated remote command execution vulnerability CVE-2025-20393.

Japan's Information-Technology Promotion Agency (IPA) has issued a security alert regarding CVE-2025-20393, an arbitrary command execution vulnerability affecting Cisco Secure Email Gateway and Secure Email and Web Manager. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on affected appliances. Cisco Systems has confirmed active exploitation of this vulnerability in the wild, indicating threat actors are already leveraging this flaw in operational attacks. IPA warns that damage may expand and strongly urges organizations to apply available patches immediately following vendor-provided procedures. Cisco has released fixed versions to address the vulnerability, and administrators should prioritize upgrading affected systems to mitigate this critical risk.

## Mentioned in this report

- Vulnerabilities: CVE-2025-20393 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260119.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8f680c1f-ef1d-403a-9f69-24e4415d343e/cisco-secure-email-gateway-and-secure-email-and-web-manager-contain-actively.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
