Cisco AsyncOS email appliance zero-day exploitation and remediation
Case score 66
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 66
- Main story score
- 63
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 1
- Vulnerability Base event: maximum-severity Cisco AsyncOS RCE with confirmed zero-day abuse. main
- Security Patch Release Cisco's fixed-release and hardening guidance for the same CVE and appliance family. context
- Campaign Direct exploitation and post-exploitation tooling tied to the same Cisco AsyncOS flaw. contributes
Overview
Latest development Open development history Cisco AsyncOS security update for CVE-2025-20393 Cisco issued fixes for **CVE-2025-20393** on **Thursday** after confirming prior **zero-day** abuse of **AsyncOS** appliances. The update closes the main code-execution path and strips persistence artifacts associated with the campaign.
-
Cisco discloses CVE-2025-20393 zero-day exploitation and releases fixes
Cisco released security updates for CVE-2025-20393 in Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager after confirming UAT-9686 exploited the maximum-severity Spam Quarantine remote command execution flaw as a zero-day. The flaw stems from insufficient validation of HTTP requests and can let an attacker execute arbitrary commands with root privileges on an affected appliance. Cisco also said the campaign included ReverseSSH (aka AquaTunnel), Chisel, AquaPurge, and AquaShell, and urged customers to secure appliances behind a firewall, monitor web log traffic, disable HTTP for the main administrator portal, disable unnecessary network services, enforce SAML or LDAP authentication, and change the default administrator password.
-
Cisco AsyncOS zero-day exploitation warning
Cisco warns that CVE-2025-20393, an unpatched maximum-severity Cisco AsyncOS zero-day, is being actively exploited against Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances with non-standard configurations when Spam Quarantine is enabled and exposed on the Internet; Cisco Talos attributes the activity to UAT-9686, says the actor deploys AquaShell, AquaTunnel, Chisel, and AquaPurge, and advises restricting access, placing appliances behind firewalls, and opening a TAC case if compromise is suspected.