CVE-2025-52691

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

  • Published Dec 29, 2025
  • CVSS 10.0 critical
  • 85.7% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A Metasploit module exploits it

Affected software

In the news

CVE-2025-52691 at the National Vulnerability Database