CVE-2025-20393
published 2025-12-17CVE-2025-20393: A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an…
PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-12-24
Exploited in the wild
EPSS
29.51%
98.0th percentile
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges.
This vulnerability is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asyncos | < 15.0.5-016 | 15.0.5-016 |
| cisco | asyncos | < 15.0.2-007 | 15.0.2-007 |
| cisco | asyncos | >= 15.5 < 15.5.4-012 | 15.5.4-012 |
| cisco | asyncos | >= 15.5 < 15.5.4-007 | 15.5.4-007 |
| cisco | asyncos | >= 16.0 < 16.0.4-016 | 16.0.4-016 |
| cisco | asyncos | >= 16.0 < 16.0.4-010 | 16.0.4-010 |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email | — | — |
| cisco | cisco_secure_email_and_web_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor Spam Quarantine web interface access logs for unusual activity, specifically the file at /data/web/euq_webui/htdocs/index.py which was used as a persistence embedding point. ↗
- →Hunt for AquaShell, AquaPurge, and AquaTunnel indicators on Cisco SEG/SEWM appliances; AquaPurge is used to clear logs, so absence of expected log entries may itself be an indicator. ↗
- →Review outbound connections from Cisco SEG/SEWM appliances to suspicious IPs, particularly the known C2 infrastructure associated with UAT-9686. ↗
- →Monitor web logs on Cisco SEG/SEWM for crafted HTTP requests targeting the Spam Quarantine interface, which is the exploitation entry point. ↗
- →Indicators of compromise for UAT-9686 activity are available in a Cisco Talos GitHub repository. ↗
- →Exploitation involves initial access via Spam Quarantine interface, followed by tunneling via AquaTunnel and Chisel for internal pivoting — monitor for unexpected reverse SSH tunnel activity originating from email gateway appliances. ↗
- ·CVE-2025-20393 only affects Cisco SEG and Cisco SEWM appliances with non-standard configurations where the Spam Quarantine feature is enabled AND exposed on the Internet. ↗
- ·If restoring the appliance is not possible and compromise is confirmed, rebuilding is currently the only viable option to eradicate the threat actor's persistence mechanism (AquaShell). ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mrgj-cg36-fgq8: Cisco is aware of a potential vulnerability
ghsa_unreviewed·2025-12-17
CVE-2025-20393 [CRITICAL] CWE-20 GHSA-mrgj-cg36-fgq8: Cisco is aware of a potential vulnerability
Cisco is aware of a potential vulnerability. Cisco is currently investigating and will update these details as appropriate as more information becomes available.
VulnCheck
Cisco Multiple Products Improper Input Validation Vulnerability
vulncheck·2025·CVSS 10.0
CVE-2025-20393 [CRITICAL] CWE-20 Cisco Multiple Products Improper Input Validation Vulnerability
Cisco Multiple Products Improper Input Validation Vulnerability
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
Affected: Cisco Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://blog.talosintelligence.com/uat-9686/; https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4; https://www.cisa.gov/sites/default/files/feeds/known_exploited
Cisco
Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
vendor_cisco·2025-12-18·CVSS 10.0
CVE-2025-20393 [CRITICAL] CWE-20 Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
On December 10, Cisco became aware of a new cyberattack campaign targeting a limited subset of appliances with certain ports open to the internet that are running Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. This attack allows the threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. The ongoing investigation has revealed evidence of a persistence mechanism implanted by the threat actors to maintain a degree of control over compromised appliances.
Cisco has remediated the vulnerability that was exploited by the threat actors as part of the cyberattack campaign. For more
CISA
Cisco Multiple Products Improper Input Validation Vulnerability
cisa·2025-12-17·CVSS 10.0
CVE-2025-20393 [CRITICAL] CWE-20 Cisco Multiple Products Improper Input Validation Vulnerability
Vulnerability: Cisco Multiple Products Improper Input Validation Vulnerability
Affected: Cisco Multiple Products
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: Please adhere to Cisco's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Cisco products affected by this vulnerability. Apply any final mitigations
Cisco
Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
vendor_cisco·CVSS 3.1
CVE-2025-20393 Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
CVE-2025-20393: Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
On December 10, Cisco became aware of a new cyberattack campaign targeting a limited subset of appliances with certain ports open to the internet that are running Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. This attack allows the threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. The ongoing investigation has revealed evidence of a persistence mechanism implanted by the threat actors to maintain a degree of control over compromised appliances. Cisco has remediated the vulnerability that was exploited by the threat actors as part of the cyberattack camp
No detection rules found.
No public exploits indexed.
Talos
IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
blogs_talos·2026-04-22
CVE-2025-20393 IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
## IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
Phishing reemerged as the most observed means of gaining initial access, accounting for over a third of the engagements where initial access could be determined. Phishing has not been the top vector for initial access since Q2 2025.
Public administration and health care tied as the most targeted industry verticals, each accounting for 24 percent of all engagements. This is the third consecutive quarter where public administration has been the most targeted industry vertical.
Pre-ransomware incidents made up just 18 percent of engagements this quarter, and we did not observe any ransomware deployment due to early and swift mitigation from Cisco Talos Incident Response
Wiz
Crying Out Cloud Monthly Newsletter - January 2026 | Wiz
blogs_wiz·2026-01-22·CVSS 8.7
CVE-2025-55182 [HIGH] Crying Out Cloud Monthly Newsletter - January 2026 | Wiz
Welcome back! In this edition, we bring you the latest in cloud security: noteworthy incidents, exclusive data, and crucial vulnerabilities. Let’s jump in.
## 🔍 Highlights
React2Shell: Critical RCE Vulnerability in React and Next.js
React2Shell (CVE-2025-55182) is a critical, unauthenticated remote code execution vulnerability rooted in insecure deserialization within the React Server Components (RSC) “Flight” protocol, impacting React 19 and RSC-enabled frameworks, most notably Next.js. The flaw affects default configurations, meaning standard production deployments can be exploited with a single crafted HTTP request and no developer misconfiguration, with exploitation demonstrating near-100% reliability.
Since early December 2025, exploitation has been observed in the wild by multipl
Bleepingcomputer
Cisco finally fixes AsyncOS zero-day exploited since November
blogs_bleepingcomputer·2026-01-16·CVSS 10.0
CVE-2025-20393 [CRITICAL] Cisco finally fixes AsyncOS zero-day exploited since November
## Cisco finally fixes AsyncOS zero-day exploited since November
## Sergiu Gatlan
Cisco has finally patched a maximum-severity Cisco AsyncOS zero-day exploited in attacks against Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances since November 2025.
As Cisco explained in December, when it disclosed the vulnerability ( CVE-2025-20393 ), it affects only Cisco SEG and Cisco SEWM appliances with non-standard configurations when the Spam Quarantine feature is enabled and exposed on the Internet.
"Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appl
Recorded Future
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
blogs_recorded_future·2026-01-13·CVSS 10.0
CVE-2025-55182 [CRITICAL] December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
## December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
December 2025 witnessed a dramatic 120% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 22 vulnerabilities requiring immediate remediation, up from 10 in November. The month was dominated by widespread exploitation of Meta's React Server Components flaw.
What security teams need to know:
React2Shell pandemonium: CVE-2025-55182 triggered a global exploitation wave with multiple threat actors deploying diverse malware families
China-nexus exploitation intensifies: Earth Lamia, Jackpot Panda, and UAT-9686 leveraged critical flaws for espionage operations
Public exploits proliferate: Eleven of 22 vulnerabilities have proof-of-concept
Bleepingcomputer
Cisco warns of Identity Service Engine flaw with exploit code
blogs_bleepingcomputer·2026-01-08·CVSS 4.9
CVE-2026-20029 [MEDIUM] Cisco warns of Identity Service Engine flaw with exploit code
## Cisco warns of Identity Service Engine flaw with exploit code
## Sergiu Gatlan
Cisco has patched a vulnerability in its Identity Services Engine (ISE) network access control solution, with public proof-of-concept exploit code, that can be abused by attackers with admin privileges.
Enterprise admins use Cisco ISE to manage endpoint, user, and device access to network resources while enforcing a zero-trust architecture.
The security flaw ( CVE-2026-20029 ) affects Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of device configuration, and remote attackers with high privileges can exploit it to access sensitive information on unpatched devices.
"This vulnerability is due to improper parsing of XML that is processed by the web-based m
Bleepingcomputer
New password spraying attacks target Cisco, PAN VPN gateways
blogs_bleepingcomputer·2025-12-18
New password spraying attacks target Cisco, PAN VPN gateways
## New password spraying attacks target Cisco, PAN VPN gateways
## Bill Toulas
An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL VPN.
On December 11, threat monitoring platform GreyNoise observed the number of login attempts aimed at GlobalProtect portals peaked at 1.7 million during a period of 16 hours.
Collected data showed that the attacks originated from more than 10,000 unique IP addresses and were aimed at infrastructure located in the United States, Mexico, and Pakistan.
The malicious traffic originated almost entirely from the 3xK GmbH (Germany) IP space, indicating a centralized cloud infrastructure.
Based on researchers' observations, the threat actor reused common usern
Bleepingcomputer
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
blogs_bleepingcomputer·2025-12-17·CVSS 10.0
CVE-2025-20393 [CRITICAL] Cisco warns of unpatched AsyncOS zero-day exploited in attacks
## Cisco warns of unpatched AsyncOS zero-day exploited in attacks
## Sergiu Gatlan
Cisco warned customers today of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances.
This yet-to-be-patched zero-day ( CVE-2025-20393 ) affects only Cisco SEG and Cisco SEWM appliances with non-standard configurations, when the Spam Quarantine feature is enabled and exposed on the Internet.
Cisco Talos, the company's threat intelligence research team, believes a Chinese threat group tracked as UAT-9686 is behind attacks abusing this security flaw to execute arbitrary commands with root and deploy AquaShell persistent backdoors, AquaTunnel and Chisel reverse SSH tunnel malware implants,
Recorded Future
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
blogs_recorded_future·CVSS 7.8
CVE-2025-55182 [HIGH] December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
# December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat Activity
December 2025 witnessed a dramatic 120% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 22 vulnerabilities requiring immediate remediation, up from 10 in November. The month was dominated by widespread exploitation of Meta's React Server Components flaw.
What security teams need to know:
- React2Shell pandemonium: CVE-2025-55182 triggered a global exploitation wave with multiple threat actors deploying diverse malware families
- China-nexus exploitation intensifies: Earth Lamia, Jackpot Panda, and UAT-9686 leveraged critical flaws for espionage operations
- Public exploits proliferate: Eleven of 22 vulnerabilities have proof-of-conce
2025-12-17
Published
2025-12-17
Added to CISA KEV
Exploited in the wild