Cisco remediated two vulnerabilities in Cisco Secure Email Gateway, led by CVE-2024-20401, a critical flaw with a CVSS score of 9.8. An unauthenticated attacker can send a specially crafted email attachment to create root users, modify appliance configuration, execute arbitrary code, or trigger persistent denial of service.
Cisco also patched CVE-2024-20429 (CVSS 6.5), a server-side template injection vulnerability that allows an authenticated operator-level user to execute code remotely as root. Cisco reported no known exploitation when the advisory was issued; organizations should apply the available software updates and Cisco mitigations promptly.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
Cisco released software updates for CVE-2024-20401 and CVE-2024-20429 in Cisco Secure Email Gateway. CVE-2024-20401 (CVSS 9.8) can allow an unauthenticated attacker using a crafted email attachment to gain root-level control, while CVE-2024-20429 (CVSS 6.5) enables authenticated operator-level code execution as root; Cisco said it was not aware of exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.