CISOOnline

Critical Cisco Secure Email Gateway zero-day gives attackers root access

If exploitation is suspected on physical devices, Cisco recommends contacting the Cisco Technical Assistance Center. For virtual devices, customers are advised to save all forensic information then deploy a new instance with rebuilt configuration and rotated credentials.

Devices that are enrolled in Cisco Secure Email Cloud have already been reviewed by Cisco and the owners of the devices that showed potential signs of compromise were contacted. The company’s advisory also includes general recommendations for device security hardening.

“A root-level, unauthenticated RCE in an email gateway is about as good a foothold as an attacker gets,” Josh Picolet, vice president of detection and analysis at security firm Team Cymru, tells CSO. “This is only the second Secure Email Gateway flaw ever added to CISA’s KEV catalog, after CVE-2025-20393, and that repetition fits actors who treat edge appliances as durable, reusable access rather than one-off targets.”



Source link