Summary
It is recommended to follow Cisco’s recommendations to check whether vulnerable appliances have been compromised, and to remediate the issue. While there is not much technical details about the vulnerability CVE-2025-20393, with a CVSS score of 10, Cisco reveals that it allows attackers to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. This vulnerability affects Cisco Secure Email Gateway, both physical and virtual, and Cisco SecureEmailandWebManagerappliances,bothphysicalandvirtual,whenbothofthefollowing It is recommended to check if Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances are configured with the Spam Quarantine feature, and if they are, that the feature is not reachable from the internet. If it is the case, it is recommended to open a Cisco Technical Assistance Center (TAC) case to verify whether an appliance has been compromised It is also recommended to follow Cisco’s recommendations to remediate the issue [1]: In case the appliance was found to be compromised, it is recommended to investigate further any lateral movement that may have occurred within the network.