CVE-2025-20393

Confirmed PUBLISHED

Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability

Cisco · Cisco Secure Email, Cisco Secure Email and Web Manager

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
10.0 Critical EPSS 29.1%

At a Glance

A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.

cisa edge
CVE Published
Dec 17, 2025
Exploitation Reported
Jun 01, 2026
CVSS
10.0 Critical
EPSS
29.1%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

44 version rows · page 2 of 2

Vendor Product Version Status
Cisco
Cisco Secure Email and Web Manager

14.0.0-404

Affected
Cisco
Cisco Secure Email and Web Manager

12.8.1-002

Affected
Cisco
Cisco Secure Email and Web Manager

14.1.0-227

Affected
Cisco
Cisco Secure Email and Web Manager

13.6.1-201

Affected
Cisco
Cisco Secure Email and Web Manager

14.2.0-203

Affected
Cisco
Cisco Secure Email and Web Manager

14.2.0-212

Affected
Cisco
Cisco Secure Email and Web Manager

12.8.1-021

Affected
Cisco
Cisco Secure Email and Web Manager

13.8.1-108

Affected
Cisco
Cisco Secure Email and Web Manager

14.2.0-224

Affected
Cisco
Cisco Secure Email and Web Manager

14.3.0-120

Affected
Cisco
Cisco Secure Email and Web Manager

15.0.0-334

Affected
Cisco
Cisco Secure Email and Web Manager

15.5.1-024

Affected
Cisco
Cisco Secure Email and Web Manager

15.5.1-029

Affected
Cisco
Cisco Secure Email and Web Manager

15.5.2-005

Affected
Cisco
Cisco Secure Email and Web Manager

16.0.0-195

Affected
Cisco
Cisco Secure Email and Web Manager

15.5.3-017

Affected
Cisco
Cisco Secure Email and Web Manager

16.0.1-010

Affected
Cisco
Cisco Secure Email and Web Manager

15.0.1-035

Affected
Cisco
Cisco Secure Email and Web Manager

16.0.2-088

Affected

CVE References

  • cisco-sa-sma-attack-N9bf4 sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.