CISA KEV · catalog date Dec 17, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2025-20393
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
Exploited in the wild (CISA KEV since Dec 17, 2025). cisco reports CVSS 3.1 10.0. EPSS estimates 29.9% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
- State
- PUBLISHED
- Published
- Dec 17, 2025
- Updated
- Feb 26, 2026
- Evidence coverage
- 96%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAciscoOriginal evidence ↗
Record text: Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
Inspect raw assertion
- Field
container- Value
- Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Cisco Multiple Products Improper Input Validation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Cisco Multiple Products Improper Input Validation Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 29.88% probability · 98.06th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.298750000000; percentile 0.980640000000
FIRST EPSS · score date Aug 26, 2026 · 98.1th percentile · first observed Aug 26, 2026
cisco · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
Inspect raw assertion
- Field
container- Value
- Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
Cisco Multiple Products Improper Input Validation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Cisco Multiple Products Improper Input Validation Vulnerability
29.88% probability · 98.06th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.298750000000; percentile 0.980640000000
Applicability
Cited product scope
Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
23 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "14.0.0-698"}, {"status": "affected", "version": "13.5.1-277"}, {"status": "affected", "version": "13.0.0-392"}, {"status": "affected", "version": "14.2.0-620"}, {"status": "affected", "version": "13.0.5-007"}, {"status": "affected", "version": "13.5.4-038"}, {"status": "affected", "version": "14.2.1-020"}, {"status": "affected", "version": "14.3.0-032"}, {"status": "affected", "version": "15.0.0-104"}, {"status": "affected", "version": "15.0.1-030"}, {"status": "affected", "version": "15.5.0-048"}, {"status": "affected", "version": "15.5.1-055"}, {"status": "affected", "version": "15.5.2-018"}, {"status": "affected", "version": "16.0.0-050"}, {"status": "affected", "version": "15.0.3-002"}, {"status": "affected", "version": "16.0.0-054"}, {"status": "affected", "version": "15.5.3-022"}, {"status": "affected", "version": "16.0.1-017"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "13.6.2-023"}, {"status": "affected", "version": "13.6.2-078"}, {"status": "affected", "version": "13.0.0-249"}, {"status": "affected", "version": "13.0.0-277"}, {"status": "affected", "version": "13.8.1-052"}, {"status": "affected", "version": "13.8.1-068"}, {"status": "affected", "version": "13.8.1-074"}, {"status": "affected", "version": "14.0.0-404"}, {"status": "affected", "version": "12.8.1-002"}, {"status": "affected", "version": "14.1.0-227"}, {"status": "affected", "version": "13.6.1-201"}, {"status": "affected", "version": "14.2.0-203"}, {"status": "affected", "version": "14.2.0-212"}, {"status": "affected", "version": "12.8.1-021"}, {"status": "affected", "version": "13.8.1-108"}, {"status": "affected", "version": "14.2.0-224"}, {"status": "affected", "version": "14.3.0-120"}, {"status": "affected", "version": "15.0.0-334"}, {"status": "affected", "version": "15.5.1-024"}, {"status": "affected", "version": "15.5.1-029"}, {"status": "affected", "version": "15.5.2-005"}, {"status": "affected", "version": "16.0.0-195"}, {"status": "affected", "version": "15.5.3-017"}, {"status": "affected", "version": "16.0.1-010"}, {"status": "affected", "version": "15.0.1-035"}, {"status": "affected", "version": "16.0.2-088"}]product-a66d712bfc0d863aac218b86803961d33040877eadd547f7c007a7c6fe2c5934Linked exactInspect raw assertions
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 16.0; through excluding 16.0.4-010
- Match ID
f29f71ef-ed63-4db2-a8ba-eb1e1a3bff09
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 15.0.2-007
- Match ID
6893ae30-31de-42cb-a463-e3de22977107
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 15.5; through excluding 15.5.4-012
- Match ID
81772a3f-141d-4c3d-8094-1bd359d07c4a
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 15.5; through excluding 15.5.4-007
- Match ID
12017942-b997-4fb1-b7ff-504ea72ac705
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 16.0; through excluding 16.0.4-016
- Match ID
32ff4e02-3750-4654-bd48-126133b33e6a
cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 15.0.5-016
- Match ID
f7005ee5-0976-4e88-933f-c451d196c057
product-bdb4c23c2fc75557a28b21b5d14ae62ee647274b4836ed85c065b90abc3605dcLinked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m170:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3057023b-ad68-4953-a780-75ea416a7b94
product-dee603d41f80fdc2a38de8c5f83203cb4234d95ba8348687f108232ec51de6aaLinked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m190:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b87164b6-4717-4968-86f7-c62eb677fc50
product-2801e98805f7238469bc9c0f6f98d33a37a98de6c2d6bdaf3311d958a13b54b9Linked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m195:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
10bd81d0-d81a-4361-b4e8-d674732a2a33
product-153fe85c55700cf47e42533500025aec2b38d05315afdfa4f7d176b357b8640cLinked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m380:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d28903f8-3c4d-4337-9721-cec108a7e2d5
product-a4e4109c4339c49e8fa34e7d6aefb45c7cea028a6b594631f950169d581dfb8bLinked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m390:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
84acd394-2e45-4e8e-a342-ac57935c7038
product-646f9287f476f27d26e814c66fabf433dd66b620a47a6e645f62f756c43b5123Linked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m390x:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6112d56b-b68b-40b0-8eb9-3315533110c7
product-f8cf0a5f98ab56ead3412c2b1bdc6cce1110b26b1751f4d10cb0f4c7e446f9c3Linked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m395:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8a1198bc-c934-4c26-887d-d599e8128fd3
product-bf30a432b2f2fca6f7d3a661518e779cf918c43459415c9c6a140bba410cc477Linked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m680:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
10374ba0-e7dd-4930-8c58-251f98b75a11
product-5e3ec50e82d49f070e44abed7bb1fcd226a160b6e20c78a02233d904d480c036Linked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m690:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd265b49-c691-44b3-a505-dc704e80313c
product-e8e0db38960def74bc394dd60eca64250c31cb0d4474954c10654f0076a1ff71Linked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m690x:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e37cfc3a-1752-4c66-bd32-cffa46c3e6ad
product-9838596af0e8c61f8e7e542c9b2bb350374479f6acb378e920c716baef237390Linked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_and_web_manager_m695:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
830693ac-a737-43b9-bbb4-e3a1c950c47f
product-c6267ac09b257645c9985ada002004fdf5008820b08efffab7ebee18d5b81f70Linked exactInspect raw assertion
cpe:2.3:a:cisco:secure_email_and_web_manager_virtual_appliance_m100v:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0c9613a5-b198-4ad2-bc74-f21abaf79174
product-971fa5fdb2596662dee04391235c90e0071dfe85776e2a17ea09266423c8dea5Linked exactInspect raw assertion
cpe:2.3:a:cisco:secure_email_and_web_manager_virtual_appliance_m300v:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
57831fd6-1cf3-4abe-81ba-2576418f9083
product-9bb793f9bc427097c03673279ed7baaf674e87f3e68190c2177cce03812599b1Linked exactInspect raw assertion
cpe:2.3:a:cisco:secure_email_and_web_manager_virtual_appliance_m600v:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
67e804ae-4743-44ad-a364-504b0ab0d9bf
product-4c56fadc029b433b2fa1db0b7867a147918c151dcff2f4b4510a52dfa69a598aLinked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_gateway_c195:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7b1322b8-1cf9-4b17-9a58-38788051ed4f
product-6c9b8788df5bfc623b60147b5f6a0e66e79d7cb6d33402d6eb1084d4b398d10dLinked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_gateway_c395:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
139a640b-1957-4953-aa88-9d373a5152d1
product-14ea35636ae6ea29581663e197f747c8eb2f6b2bb8593d691b70f14dcf6f80e7Linked exactInspect raw assertion
cpe:2.3:h:cisco:secure_email_gateway_c695:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f08ea2ad-618b-4834-a52d-73f6a4502df1
product-12f9baaad7b1cf95af389beb10c8aa8f38424c590ebeaae8f7080c6c0b329285Linked exactInspect raw assertion
cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c100v:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5b6fbc8a-8187-4903-b786-6cf341c142b5
product-c00941e33c5b6b4e32b6f35e19be2b18785253ff862a2d57a9fbfa44bc5ffe8bLinked exactInspect raw assertion
cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c300v:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
68864429-9730-43e9-96c3-20b9035bb291
product-475117954dd214e45f121387f527b7da12742e675bef9a8a184cc6c342c1ff61Linked exactInspect raw assertion
cpe:2.3:a:cisco:secure_email_gateway_virtual_appliance_c600v:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b52d8b2b-e9ae-4b02-87bd-9cf9fa95906a
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-a66d712bfc0d863aac218b86803961d33040877eadd547f7c007a7c6fe2c5934
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5237a32f-e0ef-4b10-af81-f34890598c0652a45a27-d8a5-4645-b348-01a72af721375c40b071-03de-41bc-8470-e3d588f0d2b0c6cc612b-eda2-442f-8269-1faa882b1938c8631fb0-b651-4ff1-b72d-1eff24ea59a2e814e902-5233-49ea-a2b1-d4ba575d49f9Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3dc7562a-5d83-4472-872f-820f9e2eb72658154356-4dae-4bc0-af77-876287b3027fAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDirect CVE/CNA normalized decisions
cisco
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 10.0
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.