CVE-2025-20393Critical· 10.0▾ Hadal⚠ Exploited in the wild0dayPoC availableA vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an aff…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 55 · likelihood 6.5 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Federal remediation due Dec 24, 2025
Last analysed / modified upstream
32%
4 GitHub repos (last check)
Added to the CISA catalog on Dec 17, 2025. Federal remediation due Dec 24, 2025. View catalog ↗
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.
This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
secure_email 14.0.0-698secure_email 13.5.1-277secure_email 13.0.0-392secure_email 14.2.0-620secure_email 13.0.5-007secure_email 13.5.4-038secure_email 14.2.1-020secure_email 14.3.0-032secure_email 15.0.0-104secure_email 15.0.1-030secure_email 15.5.0-048secure_email 15.5.1-055secure_email 15.5.2-018secure_email 16.0.0-050secure_email 15.0.3-002secure_email 16.0.0-054secure_email 15.5.3-022secure_email 16.0.1-017secure_email_and_web_manager 13.6.2-023secure_email_and_web_manager 13.6.2-078secure_email_and_web_manager 13.0.0-249secure_email_and_web_manager 13.0.0-277secure_email_and_web_manager 13.8.1-052secure_email_and_web_manager 13.8.1-068secure_email_and_web_manager 13.8.1-074secure_email_and_web_manager 14.0.0-404secure_email_and_web_manager 12.8.1-002secure_email_and_web_manager 14.1.0-227secure_email_and_web_manager 13.6.1-201secure_email_and_web_manager 14.2.0-203secure_email_and_web_manager 14.2.0-212secure_email_and_web_manager 12.8.1-021secure_email_and_web_manager 13.8.1-108secure_email_and_web_manager 14.2.0-224secure_email_and_web_manager 14.3.0-120secure_email_and_web_manager 15.0.0-334secure_email_and_web_manager 15.5.1-024secure_email_and_web_manager 15.5.1-029secure_email_and_web_manager 15.5.2-005secure_email_and_web_manager 16.0.0-195secure_email_and_web_manager 15.5.3-017secure_email_and_web_manager 16.0.1-010secure_email_and_web_manager 15.0.1-035secure_email_and_web_manager 16.0.2-088Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3452High· 7.5A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…
CVE-2018-15454High· 8.6A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an …
CVE-2018-0296High· 7.5A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition
CVE-2026-76504Critical· 9.8A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is …
CVE-2026-76460Critical· 10.0A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint
CVE-2020-3478High· 8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device