logo

New Tool Released to Detect Cisco Secure Email Gateway 0-Day Vulnerability Exploited in the Wild

ID: 9c38724e-bc07-5856-bab2-442e5bf20bf7

STIX ID: report--9c38724e-bc07-5856-bab2-442e5bf20bf7

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A publicly released, dependency-free Python script called "Cisco SMA Exposure Check" helps organizations detect exposure to CVE-2025-20393 — a critical unauthenticated RCE in Cisco Secure Email Gateway/SMA that is reported to be actively exploited. The tool probes admin and quarantine ports (e.g., 82, 83, 443, 8080, 8443, 9443, 6025), performs HTTP/S fingerprinting and path checks, and flags indicators of active exploitation and post-compromise tools (AquaShell, AquaTunnel, Chisel, AquaPurge), enabling rapid mitigation such as firewalling, patching, or isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.