Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild

Cisco has identified ongoing exploitation of a critical zero-day remote code execution vulnerability within its Secure Email Gateway and Secure Email and Web Manager appliances.

Cisco has identified ongoing exploitation of a critical zero-day remote code execution vulnerability within its Secure Email Gateway and Secure Email and Web Manager appliances.

The vulnerability, designated as CVE-2025-20393 , permits unauthenticated attackers to execute arbitrary root-level commands through specially crafted HTTP requests directed at the Spam Quarantine feature. This flaw arises from inadequate validation of HTTP requests in the Spam Quarantine function of Cisco AsyncOS Software, potentially allowing remote command execution with root privileges.

Classified under CWE-20 (Improper Input Validation), the vulnerability carries a maximum CVSSv3.1 base score of 10.0, reflecting its network accessibility, low attack complexity, and significant impact on confidentiality, integrity, and availability.

The vulnerability affects appliances with the Spam Quarantine feature enabled and exposed to the internet, typically on port 6025. This configuration is not enabled by default and is not recommended in deployment guides.

CVE ID CVSS Score Vector String CWE ID Bug IDs

CVE-2025-20393 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CWE-20 CSCws36549, CSCws52505

Cisco became aware of the attacks on December 10, 2025, with the first evidence of exploitation dating back to November 2025.

Cisco Talos attributes the exploitation to UAT-9686 (also known as UNC-9686), a China-linked advanced persistent threat actor. The attackers employ a Python-based backdoor named AquaShell for persistent access, alongside reverse SSH tunneling tools like AquaTunnel and Chisel. These tools facilitate internal pivoting, while AquaPurge is used for log wiping to avoid detection. Target sectors include telecommunications and critical infrastructure, with activities primarily focused on espionage.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-20393 to its Known Exploited Vulnerabilities catalog on December 17, 2025, requiring federal agencies to apply mitigations by December 24, 2025. No public proof-of-concept exploits exist as of January 2026, although automated scanning has increased.

The vulnerability affects appliances with the Spam Quarantine feature enabled and exposed to the internet, typically on port 6025.
Jonathan Pierce · Thehackingpost

Indicators of compromise include the implanted persistence mechanism, a covert channel for remote access. Cisco recommends verification through its Technical Assistance Center (TAC) support with remote access enabled.

Cisco has released patches to address the vulnerability and remove known persistence mechanisms. No workarounds are available. Administrators should upgrade immediately and verify the Spam Quarantine status via the web interface under Network > IP Interfaces.

Cisco Secure Email Gateway Fixed Releases

Vulnerable Release First Fixed Release

14.2 and earlier 15.0.5-016

15.0 15.0.5-016

15.5 15.5.4-012

16.0 16.0.4-016

Advertisement

Cisco Secure Email and Web Manager Fixed Releases

Vulnerable Release First Fixed Release

15.0 and earlier 15.0.2-007

15.5 15.5.4-007

16.0 16.0.4-010

Additional hardening measures include firewall configuration, separation of mail/management interfaces, disabling unnecessary services such as HTTP/FTP, and employing strong authentication protocols such as SAML or LDAP.

Cisco Secure Email Cloud services are unaffected. Organizations should monitor logs externally and contact TAC for compromise assessment.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories