100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild
Security researchers have identified a critical zero-day vulnerability in at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices, which attackers are actively exploiting.
Security researchers have identified a critical zero-day vulnerability in at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices, which attackers are actively exploiting.
The vulnerability, tracked as CVE-2025-20393 , currently lacks an available patch, exposing organizations to potential compromise.
Threat intelligence from Shadowserver Foundation indicates that these vulnerable devices are part of over 650 fingerprinted Cisco email security appliances accessible on the internet.
This discovery raises significant concerns for organizations that rely on these systems to filter malicious emails and protect their networks from phishing attacks and malware distribution.
The vulnerability, tracked as CVE-2025-20393 , currently lacks an available patch, exposing organizations to potential compromise.
CVE-2025-20393 targets Cisco's email security infrastructure, which enterprises use to inspect incoming and outgoing email traffic for threats. The confirmation of active exploitation indicates that threat actors are already leveraging this weakness to compromise vulnerable systems.
Cisco has acknowledged the vulnerability and issued a security advisory urging organizations to implement immediate defensive measures. The company recommends affected customers review their security configurations and apply temporary mitigations until a permanent fix becomes available. Detailed guidance can be accessed through Cisco's Security Advisory portal .
The situation underscores the ongoing challenges organizations face with zero-day vulnerabilities, particularly in critical infrastructure components like email gateways. These devices play a crucial role in enterprise networks, handling sensitive communications and serving as a primary defense against email-borne threats. A successful compromise could allow attackers to intercept confidential communications, deploy ransomware, or establish persistent network access.
Security teams managing Cisco Secure Email Gateway and Web Manager deployments should prioritize reviewing the advisory and implementing recommended countermeasures immediately. Organizations should also monitor their systems for suspicious activity and consider temporarily restricting external access to these devices until patches become available.
The vendor has not provided a timeline for when a security update will be released, making interim protective measures essential for minimizing exposure to this actively exploited vulnerability.
Based on reporting by Cyber Security News.
