Government cyber agencies in Belgium and Canada warned of a critical unauthenticated OS command injection vulnerability in IceWarp (tracked as CVE-2025-14500, CVSS 9.8) that can allow a remote attacker to execute arbitrary commands on affected servers. The flaw is described as CWE-78 and is tied to improper validation of user-controlled input in the X-File-Operation HTTP header, enabling code execution with high privileges (e.g., SYSTEM on Windows or root on Linux), with severe impact to confidentiality, integrity, and availability.
Both advisories urge immediate patching across impacted IceWarp product lines and versions, including IceWarp Epos Update 2, Epos Update 1, Epos (1st generation), and Deep Castle and older versions. Recommended fixed versions include upgrading to 14.2.0.12+ (Epos Update 2), 14.1.0.20+ (Epos Update 1), 14.0.0.18+ (Epos 1st gen), and 13.0.3.13+ (Deep Castle/older), alongside heightened monitoring and detection while remediation is underway.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-20, Belgium's Centre for Cybersecurity issued a warning urging organizations to patch a critical OS command injection vulnerability in IceWarp immediately. The alert amplified the need to apply IceWarp's available fixes.
On 2026-02-19, IceWarp published security advisories covering vulnerabilities across multiple IceWarp products, including at least one critical flaw. The advisories said several IceWarp Epos release lines and the Deep Castle and older line were affected up to specified version thresholds, and provided security update information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.