logo

CVE-2025-20393: Threat Campaign Targeting Cisco Secure Email Gateway, Cisco Secure Email and Web Manager

ID: 9bc71b0a-7469-5c1e-afd1-f48b0b9c04cf

STIX ID: report--9bc71b0a-7469-5c1e-afd1-f48b0b9c04cf

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2025-12-19

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

Cisco disclosed an active campaign exploiting a zero-day (CVE-2025-20393) in Cisco AsyncOS Spam Quarantine that allows root-level command execution on affected Secure Email Gateway and Secure Email and Web Manager appliances; Cisco Talos observed deployment of the AquaShell backdoor and attributes the activity to UAT-9686 (moderate confidence, China-affiliated). Cisco and Arctic Wolf advise removing the Spam Quarantine service from the public internet, filtering access to trusted hosts, monitoring for IOCs, contacting Cisco TAC for inspections, and applying patches when released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.