CVE-2025-14500Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the X-File-Operation header. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-27394.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 26 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 22 signals
  • Disclosure: 10 classified signals
  • General: 9 classified signals
  • Peaked 6d ago at 9 mentions (2026-03-04); latest day: 1
  • 26 total mentions across 11 days

Deep dive

Activity timeline26 mentions / 11d
02579Mentions · 2026-02-20: 1Mentions · 2026-02-27: 1Mentions · 2026-03-02: 2Mentions · 2026-03-03: 2Mentions · 2026-03-04: 9Mentions · 2026-03-05: 5Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-18: 2Mentions · 2026-08-08: 1Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-03-18: 2Exploit Tool / Code · 2026-03-18: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-18: 2Technical Details · 2026-02-20: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 9Technical Details · 2026-03-05: 5Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-18: 202-2002-2703-0203-0303-0403-0503-0603-0703-1808-0808-20
Signal classification4 categories
Disclosure
1038.5%
General
934.6%
Patch
519.2%
PoC
27.7%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-02-201
Patch1
2026-02-271
Disclosure1
2026-03-022
General1Patch1
2026-03-032
General1Patch1
2026-03-049
Disclosure4General4Patch1
2026-03-055
Disclosure3General1Patch1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
2026-03-182
PoC2
2026-08-081
General1
2026-08-201
General1
Full discourse20 posts
  • The Shadowserver Foundation@Shadowserver
    Patch

    We are scanning & reporting IceWarp CVE-2025-14500 (CVSS 9.8, pre-auth command injection RCE) instances. 1278 IPs seen 2026-03-01 (version based check). Patch info: https://support.icewarp.com/hc/en-us/community/posts/40040980098705-EPOS-Update-2-build-9-14-2-0-9 IP data in https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ Dashboard World Map view: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-14500%2B&data_set=count&scale=log&auto_update=on https://t.co/x0Gy15ucCv

    Post summary

    The post reports scanning of 1,278 IPs vulnerable to IceWarp CVE-2025-14500, provides a patch link, and shares vulnerability details but no exploit or PoC.

    216038155.0K
    21.6K followersView on X
  • XENOPS@XENOPSAE
    General

    We took a look at IceWarp's CVE-2025-14500. Interesting one to pull apart. https://xenops.ae/blog/one-byte-is-plenty

    Post summary

    Brief note referencing IceWarp's CVE-2025-14500 without containing proof‑of‑concept links, exploitation details, or mitigation information.

    040621.1K
    11 followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    General

    Over 1,200 IceWarp servers still vulnerable to unauthenticated RCE flaw (CVE-2025-14500) https://www.helpnetsecurity.com/2026/03/04/icewarp-rce-cve-2025-14500/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet reports that more than 1,200 IceWarp servers remain affected by CVE‑2025‑14500, an unauthenticated remote code execution vulnerability, but provides no evidence of exploits, patches, or active attacks.

    22040766
    193.5K followersView on X
  • ET Labs@ET_Labs
    General

    46 new OPEN, 48 new PRO (46 + 2) ClickFix, CVE-2025-14500, EtherHiding https://community.emergingthreats.net/t/ruleset-update-summary-2026-08-20-v11261/3425

    Post summary

    This is a concise update from Emerging Threats noting new rules—including one for CVE‑2025‑14500—without providing exploitation details, patches, or technical data.

    03021375
    5.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical OS Command Injection vulnerability in #IceWarp. #CVE-2025-14500 (CVSS: 9.8). Unauthenticated attackers can achieve complete system compromise #RCE #Patch #Patch #Patch More info: https://ccb.belgium.be/advisories/warning-critical-os-command-injection-vulnerability-icewarp-patch-immediately

    Post summary

    A critical OS command injection vulnerability (CVE-2025-14500) in IceWarp is disclosed, stressing a high CVSS score and urging immediate patching, with no PoC, exploit code, or active exploitation reported.

    01032341
    7.2K followersView on X
  • Ethical Hacking Consultores@EHCGroup
    Patch

    Más de 1200 servidores IceWarp siguen siendo vulnerables a la falla RCE no autenticada (CVE-2025-14500). El fallo permite a atacantes tomar control total de servidores de correo. Si usas IceWarp ¡actualiza a la versión 13.0.4 de inmediato! #ciberseguridad https://www.linkedin.com/pulse/m%C3%A1s-de-1200-servidores-icewarp-siguen-siendo-vulnerables-la-falla-226ye

    Post summary

    More than 1,200 IceWarp servers are still vulnerable to CVE-2025-14500, an unauthenticated RCE. Users are urged to update immediately to version 13.0.4.

    01020170
    4.1K followersView on X
  • Oscar@OscarOPS
    Patch

    Over 1,200 IceWarp servers remain exposed to CVE-2025-14500, an unauthenticated RCE flaw. EU-heavy install base makes this a quiet but serious exposure. If your org uses IceWarp for email or collaboration, verify your patch status today.

    Post summary

    The message alerts that over 1,200 IceWarp servers remain vulnerable to CVE‑2025‑14500, an unauthenticated RCE, and urges users to confirm and apply the appropriate patch.

    1001098
    25 followersView on X
  • キタきつね@foxbook
    General

    1,200台以上のIceWarpサーバーが、認証されていないリモートコード実行の脆弱性(CVE-2025-14500)に対して依然として脆弱です Over 1,200 IceWarp servers still vulnerable to unauthenticated RCE flaw (CVE-2025-14500) #HelpNetSecurity (Mar 4) https://www.helpnetsecurity.com/2026/03/04/icewarp-rce-cve-2025-14500/

    Post summary

    The post reports that more than 1,200 IceWarp servers remain vulnerable to the unauthenticated RCE flaw CVE‑2025‑14500, with no PoC, exploit code, active exploitation evidence, or patch information provided.

    00020303
    4.7K followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    Over 1,200 IceWarp servers still vulnerable to unauthenticated RCE flaw (CVE-2025-14500): A critical RCE vulnerability (CVE-2025-14500) in IceWarp, an EU-made business communication and collaboration platform, may be exploited by attackers to gain… https://www.helpnetsecurity.com/2026/03/04/icewarp-rce-cve-2025-14500/?utm_source=dlvr.it&utm_medium=twitter https://t.co/kxm7U49B9u

    Post summary

    The tweet notes that over 1,200 IceWarp servers remain vulnerable to the unauthenticated RCE flaw CVE‑2025‑14500, highlighting the severity but not confirming active exploitation or available fixes.

    01100274
    2.2K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    If you receive an alert from us, please update! NVD entry: https://nvd.nist.gov/vuln/detail/cve-2025-14500 Background: https://www.zerodayinitiative.com/advisories/ZDI-25-1072/

    Post summary

    The message merely references CVE‑2025‑14500 and provides links to the NVD entry and a ZDI advisory, without additional technical or exploit information.

    00011906
    21.6K followersView on X
  • Brian Teater@bteater51
    Disclosure

    Over 1,200 IceWarp servers still vulnerable to unauthenticated RCE flaw (CVE-2025-14500) https://www.helpnetsecurity.com/2026/03/04/icewarp-rce-cve-2025-14500/

    Post summary

    The article announces that over 1,200 IceWarp servers remain vulnerable to an unauthenticated remote code execution flaw, CVE-2025-14500.

    0001097
    1.2K followersView on X
  • Help Net Security@helpnetsecurity
    General

    Over 1,200 IceWarp servers still vulnerable to unauthenticated RCE flaw (CVE-2025-14500) - https://www.helpnetsecurity.com/2026/03/04/icewarp-rce-cve-2025-14500/ - @Shadowserver #CVE #Enterprise #SMBs #SecurityUpdate #Cybersecurity #CybersecurityNews

    Post summary

    The post alerts that over 1,200 IceWarp servers remain vulnerable to an unauthenticated remote code execution flaw (CVE‑2025‑14500) without reference to a PoC, exploit, or mitigation.

    00010433
    60.0K followersView on X
  • Eric Vanderburg@evanderburg
    General

    Over 1,200 #IceWarp servers still vulnerable to unauthenticated RCE flaw (#CVE-2025-14500) http://securitytc.com/TRHdwP https://t.co/V26QLUDT1m

    Post summary

    The tweet highlights that more than 1,200 IceWarp servers remain vulnerable to CVE‑2025‑14500, an unauthenticated remote code‑execution flaw, but makes no claims about active exploitation, patches, or proof‑of‑concept details.

    00010145
    44.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-21513 2 - CVE-2025-14500 3 - CVE-2026-21236 4 - CVE-2026-2441 5 - CVE-2026-3223 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists trending CVE identifiers without providing additional technical or operational details.

    00010166
    1.7K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @rangeva - CVE-2025-14500 (IceWarp): An OS command injection vulnerability in the X-File-Operation header that allows unauthenticated remote attackers to execute arbitrary code with SYSTEM or root privileges. 🛠️ #Exploit #Security

    Post summary

    The tweet announces CVE-2025-14500 as an OS command injection flaw in IceWarp that enables unauthenticated attackers to gain SYSTEM or root privileges, but it offers no proof of exploitation, PoC, or patch details.

    1000083
    317 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #IceWarp: disponibile #PoC per lo sfruttamento della CVE-2025-14500 Rischio: 🟠 Tipologia 🔸 Remote Code Execution 🔸 Authentication Bypass 🔗 https://www.acn.gov.it/portale/en/w/icewarp-disponibile-poc-per-lo-sfruttamento-della-cve-2025-14500 ⚠ Importante aggiornare i software interessati https://t.co/vxJ9mCh1nF

    Post summary

    The tweet announces a proof of concept for CVE‑2025‑14500 targeting IceWarp, highlighting Remote Code Execution and Authentication Bypass capabilities, and urges users to apply patches, but provides no evidence of active exploitation or detailed exploit code.

    00000110
    608 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #IceWarp: disponibile #PoC per lo sfruttamento della CVE-2025-14500 Rischio: 🟠 Tipologia 🔸Remote Code Execution 🔸Authentication Bypass 🔸Security Restrictions Bypass 🔗 https://www.acn.gov.it/portale/en/w/icewarp-disponibile-poc-per-lo-sfruttamento-della-cve-2025-14500 ⚠ Importante aggiornare i software inter… https://x.com/csirt_it/status/2034293931077149161/photo/1

    Post summary

    The post announces that a Proof of Concept for CVE‑2025‑14500 in IceWarp is available, details the RCE and bypass aspects, and urges users to update their software.

    00000108
    608 followersView on X
  • Captain Kirk@captainkirk_15
    Disclosure

    1300 IceWarp-servers via kritieke kwetsbaarheid op afstand over te nemen; https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-14500%2B&data_set=count&scale=log&auto_update=on

    Post summary

    The message reports that 1,300 IceWarp servers are vulnerable to CVE-2025-14500, highlighting the potential for remote takeover and referencing a Shadowserver dashboard for evidence.

    00000260
    152 followersView on X
  • Larry Copeland Jr.@lcopelandjr
    Disclosure

    Over 1,200 IceWarp servers still vulnerable to unauthenticated RCE flaw (CVE-2025-14500) https://www.helpnetsecurity.com/2026/03/04/icewarp-rce-cve-2025-14500/

    Post summary

    The post reports that more than 1,200 IceWarp servers remain exposed to CVE‑2025‑14500, an unauthenticated remote code execution vulnerability, with no mention of a patch or PoC.

    00000125
    92 followersView on X
  • Oscar@OscarOPS
    Disclosure

    Source: Over 1,200 IceWarp servers still vulnerable to unauthenticated RCE flaw https://www.helpnetsecurity.com/2026/03/04/icewarp-rce-cve-2025-14500/

    Post summary

    The article reports that over 1,200 IceWarp servers remain vulnerable to an unauthenticated RCE flaw, yet it does not provide any PoC, exploit code, active exploitation evidence, or patch information.

    00000101
    25 followersView on X

Explore more