Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild
Cisco has identified ongoing exploitation of a critical zero-day remote code execution vulnerability within its Secure Email Gateway and Secure Email and Web Manager appliances.
Cisco has identified ongoing exploitation of a critical zero-day remote code execution vulnerability within its Secure Email Gateway and Secure Email and Web Manager appliances.
The vulnerability, designated as CVE-2025-20393 , permits unauthenticated attackers to execute arbitrary root-level commands through specially crafted HTTP requests directed at the Spam Quarantine feature. This flaw arises from inadequate validation of HTTP requests in the Spam Quarantine function of Cisco AsyncOS Software, potentially allowing remote command execution with root privileges.
Classified under CWE-20 (Improper Input Validation), the vulnerability carries a maximum CVSSv3.1 base score of 10.0, reflecting its network accessibility, low attack complexity, and significant impact on confidentiality, integrity, and availability.
The vulnerability affects appliances with the Spam Quarantine feature enabled and exposed to the internet, typically on port 6025. This configuration is not enabled by default and is not recommended in deployment guides.
CVE ID CVSS Score Vector String CWE ID Bug IDs
CVE-2025-20393 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-20 CSCws36549, CSCws52505
Cisco became aware of the attacks on December 10, 2025, with the first evidence of exploitation dating back to November 2025.
Cisco Talos attributes the exploitation to UAT-9686 (also known as UNC-9686), a China-linked advanced persistent threat actor. The attackers employ a Python-based backdoor named AquaShell for persistent access, alongside reverse SSH tunneling tools like AquaTunnel and Chisel. These tools facilitate internal pivoting, while AquaPurge is used for log wiping to avoid detection. Target sectors include telecommunications and critical infrastructure, with activities primarily focused on espionage.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-20393 to its Known Exploited Vulnerabilities catalog on December 17, 2025, requiring federal agencies to apply mitigations by December 24, 2025. No public proof-of-concept exploits exist as of January 2026, although automated scanning has increased.
The vulnerability affects appliances with the Spam Quarantine feature enabled and exposed to the internet, typically on port 6025.
Indicators of compromise include the implanted persistence mechanism, a covert channel for remote access. Cisco recommends verification through its Technical Assistance Center (TAC) support with remote access enabled.
Cisco has released patches to address the vulnerability and remove known persistence mechanisms. No workarounds are available. Administrators should upgrade immediately and verify the Spam Quarantine status via the web interface under Network > IP Interfaces.
Cisco Secure Email Gateway Fixed Releases
Vulnerable Release First Fixed Release
14.2 and earlier 15.0.5-016
15.0 15.0.5-016
15.5 15.5.4-012
16.0 16.0.4-016
Cisco Secure Email and Web Manager Fixed Releases
Vulnerable Release First Fixed Release
15.0 and earlier 15.0.2-007
15.5 15.5.4-007
16.0 16.0.4-010
Additional hardening measures include firewall configuration, separation of mail/management interfaces, disabling unnecessary services such as HTTP/FTP, and employing strong authentication protocols such as SAML or LDAP.
Cisco Secure Email Cloud services are unaffected. Organizations should monitor logs externally and contact TAC for compromise assessment.
Based on reporting by Cyber Security News.
