Secure Email and Web

CVE-2025-20393: Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.

Published

ExploitedYes, in CISA KEVAdded 17 Dec 2025
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 10
EPSS32%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Cisco Secure Email 14.0See the advisory
Cisco Secure Email 13.5See the advisory
Cisco Secure Email 13.0See the advisory
Cisco Secure Email 14.2See the advisory
Cisco Secure Email 13.0See the advisory
Cisco Secure Email 13.5See the advisory
Cisco Secure Email 14.2See the advisory
Cisco Secure Email 14.3See the advisory
Cisco Secure Email 15.0See the advisory
Cisco Secure Email 15.0See the advisory
Cisco Secure Email 15.5See the advisory
Cisco Secure Email 15.5See the advisory
Cisco Secure Email 15.5See the advisory
Cisco Secure Email 16.0See the advisory
Cisco Secure Email 15.0See the advisory
Cisco Secure Email 16.0See the advisory
Cisco Secure Email 15.5See the advisory
Cisco Secure Email 16.0See the advisory
Cisco Secure Email and Web Manager 13.6See the advisory
Cisco Secure Email and Web Manager 13.6See the advisory
Cisco Secure Email and Web Manager 13.0See the advisory
Cisco Secure Email and Web Manager 13.0See the advisory
Cisco Secure Email and Web Manager 13.8See the advisory
Cisco Secure Email and Web Manager 13.8See the advisory
Cisco Secure Email and Web Manager 13.8See the advisory
Cisco Secure Email and Web Manager 14.0See the advisory
Cisco Secure Email and Web Manager 12.8See the advisory
Cisco Secure Email and Web Manager 14.1See the advisory
Cisco Secure Email and Web Manager 13.6See the advisory
Cisco Secure Email and Web Manager 14.2See the advisory
Cisco Secure Email and Web Manager 14.2See the advisory
Cisco Secure Email and Web Manager 12.8See the advisory
Cisco Secure Email and Web Manager 13.8See the advisory
Cisco Secure Email and Web Manager 14.2See the advisory
Cisco Secure Email and Web Manager 14.3See the advisory
Cisco Secure Email and Web Manager 15.0See the advisory
Cisco Secure Email and Web Manager 15.5See the advisory
Cisco Secure Email and Web Manager 15.5See the advisory
Cisco Secure Email and Web Manager 15.5See the advisory
Cisco Secure Email and Web Manager 16.0See the advisory
Cisco Secure Email and Web Manager 15.5See the advisory
Cisco Secure Email and Web Manager 16.0See the advisory
Cisco Secure Email and Web Manager 15.0See the advisory
Cisco Secure Email and Web Manager 16.0See the advisory

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.

This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

Exploitation

In December 2025, the Cisco Product Security Incident Response Team (PSIRT) became aware of potentially malicious activity that targets Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances.

CISA lists this CVE as exploited in the wild since 17 Dec 2025.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.