CVE-2025-25235: Omnissa Secure Email Gateway

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traffic such as HTTP requests to internal networks.

Affected products

Published 2025-08-11. Last modified 2026-06-17.