Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Campaign Security Patch Release

Cisco AsyncOS email appliance zero-day exploitation and remediation

Updated 16.01.2026 07:38
Case score 66
Members 3 First seen 17.12.2025 20:45 Latest activity 16.01.2026 07:38

Overview

**CVE-2025-20393** in **Cisco AsyncOS** is being actively used against **Cisco Secure Email Gateway** and **Cisco Secure Email and Web Manager** appliances when **Spam Quarantine** is internet-reachable. Cisco said **UAT-9686** used the flaw as a zero-day to gain root command execution and establish persistence with tunneling and log-clearing tooling. Cisco has released fixes and hardening guidance, and confirmed compromises may require rebuilding the appliance to clear persistence. **CVE-2025-20393** is also in **CISA's KEV** catalog, while the full reach of the activity remains unquantified.
Latest development Open development history 2 earlier developments Cisco AsyncOS security update for CVE-2025-20393 Cisco issued fixes for **CVE-2025-20393** on **Thursday** after confirming prior **zero-day** abuse of **AsyncOS** appliances. The update closes the main code-execution path and strips persistence artifacts associated with the campaign.
  1. Earlier development

    Cisco discloses CVE-2025-20393 zero-day exploitation and releases fixes

    Cisco released security updates for CVE-2025-20393 in Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager after confirming UAT-9686 exploited the maximum-severity Spam Quarantine remote command execution flaw as a zero-day. The flaw stems from insufficient validation of HTTP requests and can let an attacker execute arbitrary commands with root privileges on an affected appliance. Cisco also said the campaign included ReverseSSH (aka AquaTunnel), Chisel, AquaPurge, and AquaShell, and urged customers to secure appliances behind a firewall, monitor web log traffic, disable HTTP for the main administrator portal, disable unnecessary network services, enforce SAML or LDAP authentication, and change the default administrator password.

  2. Earlier development

    Cisco AsyncOS zero-day exploitation warning

    Cisco warns that CVE-2025-20393, an unpatched maximum-severity Cisco AsyncOS zero-day, is being actively exploited against Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances with non-standard configurations when Spam Quarantine is enabled and exposed on the Internet; Cisco Talos attributes the activity to UAT-9686, says the actor deploys AquaShell, AquaTunnel, Chisel, and AquaPurge, and advises restricting access, placing appliances behind firewalls, and opening a TAC case if compromise is suspected.

Signals

Exploitation
CVEs/products
Remediation
Status
Threat context

Threat actor context

3 listed

Malware & tooling context

2 families · 5 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Cisco AsyncOS Spam Quarantine RCE (CVE-2025-20393)
Updated 16.01.2026 07:38 Lead Contribution 63
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

**CVE-2025-20393** is a **maximum-severity** flaw in **Cisco AsyncOS Software** that affects **Cisco Secure Email Gateway** and **Cisco Secure Email and Web Manager** appliances when **Spam Quarantine** is enabled and reachable from the internet. Cisco said the issue was **actively exploited as a zero-day** by **UAT-9686**, who used it to gain **root-level command execution**, establish **persistence**, and deploy tools including **ReverseSSH (aka AquaTunnel)**, **Chisel**, **AquaPurge**, and **AquaShell**. Cisco has released security updates, and **CISA** added the CVE to **KEV**. The company also advised customers to reduce exposure by limiting internet access, disabling unnecessary services, and hardening appliance access controls.

Campaign UAT-9686 Cisco AsyncOS exploitation and persistence campaign
Updated 17.12.2025 20:45 Scoring Support Contribution 2
Campaign Active Patch No Patch

The **UAT-9686** campaign is actively exploiting **CVE-2025-20393** on **Cisco AsyncOS** email appliances, giving attackers **root command execution** and a foothold for persistence. The activity targets **Secure Email Gateway (SEG)** and **Secure Email and Web Manager (SEWM)** appliances exposed through **Spam Quarantine** configurations on the Internet. Cisco first spotted the attacks on **December 10** and says the operation has been active since at least **late November 2025**.

Security Patch Release Cisco AsyncOS security update for CVE-2025-20393
Updated 16.01.2026 07:38 Context
Exploitation Active Exploitation CVSS 10.0 Critical Urgency High Patch Patch Available

Cisco released **security updates** for **CVE-2025-20393** in **Cisco AsyncOS Software** for **Cisco Secure Email Gateway** and **Cisco Secure Email and Web Manager**, closing a **maximum-severity** remote-command-execution flaw. The fix matters because the vulnerability had already been used as a **zero-day** and could grant attackers **root privileges** on affected appliances. Cisco also removed persistence mechanisms linked to the attack campaign. Administrators need to move to the fixed AsyncOS releases and harden exposure around the affected email security systems.