
As of early March 2026, over 1,200 internet-facing IceWarp servers remain vulnerable to a critical unauthenticated Remote Code Execution (RCE) flaw, tracked as CVE-2025-14500. The Shadowserver Foundation reported identifying 1,278 vulnerable instances as of March 1, 2026.
Vulnerability Overview
X-File-Operation header.Patching and Mitigation
IceWarp released security updates to address this flaw in late 2025. Users are urged to back up their servers and upgrade to at least the following versions:
The Centre for Cybersecurity Belgium (CCB) warns that while patching protects against future attacks, it does not remediate any compromises that may have occurred before the patch was applied.
#1,200 #critical #cve-2025-14500 #flaw #global #icewarp #more #news #servers #still #than #threatens — News
© Bulletproof Servers. All rights reserved.