Answer in brief
CVE-2025-20393 records a High severity vulnerability in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability. The current sources mark it as known exploited. The current feed maps Cisco/Cisco Secure Email (generic), Cisco/Cisco Secure Email and Web Manager (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Cisco/Cisco Secure Email (generic), Cisco/Cisco Secure Email and Web Manager (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco Secure Emailgeneric | 14.0.0-698 || 13.5.1-277 || 13.0.0-392 || 14.2.0-620 || 13.0.5-007 || 13.5.4-038 || 14.2.1-020 || 14.3.0-032 || 15.0.0-104 || 15.0.1-030 || 15.5.0-048 || 15.5.1-055 || 15.5.2-018 || 16.0.0-050 || 15.0.3-002 || 16.0.0-054 || 15.5.3-022 || 16.0.1-017 | Not reported |
| Cisco/Cisco Secure Email and Web Managergeneric | 13.6.2-023 || 13.6.2-078 || 13.0.0-249 || 13.0.0-277 || 13.8.1-052 || 13.8.1-068 || 13.8.1-074 || 14.0.0-404 || 12.8.1-002 || 14.1.0-227 || 13.6.1-201 || 14.2.0-203 || 14.2.0-212 || 12.8.1-021 || 13.8.1-108 || 14.2.0-224 || 14.3.0-120 || 15.0.0-334 || 15.5.1-024 || 15.5.1-029 || 15.5.2-005 || 16.0.0-195 || 15.5.3-017 || 16.0.1-010 || 15.0.1-035 || 16.0.2-088 | Not reported |
Published upstream
Dec 17, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Feb 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Dec 17, 2025
Evidence: source:kev:kev:kev:recordA vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-20393 records a High severity vulnerability in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability. The current sources mark it as known exploited. The current feed maps Cisco/Cisco Secure Email (generic), Cisco/Cisco Secure Email and Web Manager (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Cisco/Cisco Secure Email (generic), Cisco/Cisco Secure Email and Web Manager (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco Secure Emailgeneric | 14.0.0-698 || 13.5.1-277 || 13.0.0-392 || 14.2.0-620 || 13.0.5-007 || 13.5.4-038 || 14.2.1-020 || 14.3.0-032 || 15.0.0-104 || 15.0.1-030 || 15.5.0-048 || 15.5.1-055 || 15.5.2-018 || 16.0.0-050 || 15.0.3-002 || 16.0.0-054 || 15.5.3-022 || 16.0.1-017 | Not reported |
| Cisco/Cisco Secure Email and Web Managergeneric | 13.6.2-023 || 13.6.2-078 || 13.0.0-249 || 13.0.0-277 || 13.8.1-052 || 13.8.1-068 || 13.8.1-074 || 14.0.0-404 || 12.8.1-002 || 14.1.0-227 || 13.6.1-201 || 14.2.0-203 || 14.2.0-212 || 12.8.1-021 || 13.8.1-108 || 14.2.0-224 || 14.3.0-120 || 15.0.0-334 || 15.5.1-024 || 15.5.1-029 || 15.5.2-005 || 16.0.0-195 || 15.5.3-017 || 16.0.1-010 || 15.0.1-035 || 16.0.2-088 | Not reported |
Published upstream
Dec 17, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Feb 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Dec 17, 2025
Evidence: source:kev:kev:kev:recordA vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Quoted source text, attributed separately from HOL analysis.