CVE-2025-20393

Confirmed PUBLISHED

Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability

Cisco · Cisco Secure Email, Cisco Secure Email and Web Manager

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
10.0 Critical EPSS 29.1%

At a Glance

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

cisa edge
CVE Published
Dec 17, 2025
Exploitation Reported
Jun 01, 2026
CVSS
10.0 Critical
EPSS
29.1%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

44 version rows · page 1 of 2

Vendor Product Version Status
Cisco
Cisco Secure Email

14.0.0-698

Affected
Cisco
Cisco Secure Email

13.5.1-277

Affected
Cisco
Cisco Secure Email

13.0.0-392

Affected
Cisco
Cisco Secure Email

14.2.0-620

Affected
Cisco
Cisco Secure Email

13.0.5-007

Affected
Cisco
Cisco Secure Email

13.5.4-038

Affected
Cisco
Cisco Secure Email

14.2.1-020

Affected
Cisco
Cisco Secure Email

14.3.0-032

Affected
Cisco
Cisco Secure Email

15.0.0-104

Affected
Cisco
Cisco Secure Email

15.0.1-030

Affected
Cisco
Cisco Secure Email

15.5.0-048

Affected
Cisco
Cisco Secure Email

15.5.1-055

Affected
Cisco
Cisco Secure Email

15.5.2-018

Affected
Cisco
Cisco Secure Email

16.0.0-050

Affected
Cisco
Cisco Secure Email

15.0.3-002

Affected
Cisco
Cisco Secure Email

16.0.0-054

Affected
Cisco
Cisco Secure Email

15.5.3-022

Affected
Cisco
Cisco Secure Email

16.0.1-017

Affected
Cisco
Cisco Secure Email and Web Manager

13.6.2-023

Affected
Cisco
Cisco Secure Email and Web Manager

13.6.2-078

Affected
Cisco
Cisco Secure Email and Web Manager

13.0.0-249

Affected
Cisco
Cisco Secure Email and Web Manager

13.0.0-277

Affected
Cisco
Cisco Secure Email and Web Manager

13.8.1-052

Affected
Cisco
Cisco Secure Email and Web Manager

13.8.1-068

Affected
Cisco
Cisco Secure Email and Web Manager

13.8.1-074

Affected

CVE References

  • cisco-sa-sma-attack-N9bf4 sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.