Critical IceWarp Flaw CVE-2025-14500 Still Threatens More Than 1,200 Global Servers
Mar 4, 2026 // 17:11 - Niko Dunn


As of early March 2026, over 1,200 internet-facing IceWarp servers remain vulnerable to a critical unauthenticated Remote Code Execution (RCE) flaw, tracked as CVE-2025-14500. The Shadowserver Foundation reported identifying 1,278 vulnerable instances as of March 1, 2026.

Vulnerability Overview

  • Severity: Critical, with a CVSS score of 9.8.
  • Nature: An OS command injection vulnerability in the application’s handling of the X-File-Operation header.
  • Impact: Allows unauthenticated remote attackers to execute arbitrary system commands with SYSTEM or root privileges, potentially leading to full server compromise.
  • Scope: Affects both Windows and Linux deployments.

Patching and Mitigation

IceWarp released security updates to address this flaw in late 2025. Users are urged to back up their servers and upgrade to at least the following versions:

  • IceWarp Epos Update 2: Version 14.2.0.9 or newer.
  • IceWarp Epos Update 1: Version 14.1.0.19 or newer.
  • IceWarp Epos (1st Gen): Version 14.0.0.18 or newer.
  • Deep Castle (and older): Version 13.0.3.13 or newer.

The Centre for Cybersecurity Belgium (CCB) warns that while patching protects against future attacks, it does not remediate any compromises that may have occurred before the patch was applied.

#1,200  #critical  #cve-2025-14500  #flaw  #global  #icewarp  #more  #news  #servers  #still  #than  #threatens   —   News