Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild
ID: 14d9b731-0421-597e-a926-316daf4790e2
STIX ID: report--14d9b731-0421-597e-a926-316daf4790e2
Feed Name: cybersecurityNews.com
Cisco confirmed active exploitation of a critical zero-day (CVE-2025-20393) in its Secure Email Gateway and Secure Email and Web Manager that enables unauthenticated root remote code execution via the Spam Quarantine feature; Cisco attributes the campaign to China-nexus APT UAT-9686 using a Python backdoor (AquaShell), reverse SSH/tunneling tools (AquaTunnel, Chisel) and log-wiping (AquaPurge), and recommends immediate patching to fixed releases, TAC-assisted compromise assessment, and network hardening — CISA added the CVE to its Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
