CVE-2025-52691
Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.
- Published Dec 29, 2025
- CVSS 10.0 critical
- 85.7% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
Affected software
In the news
- APT and financial attacks on industrial organizations in Q2 2026 Kaspersky ICS CERT ·
- Quantifying 2026 Routinely Targeted Vulnerabilities (So Far) VulnCheck Blog ·