logo

CVE-2025-20393: Threat Campaign Targeting Cisco Secure Email Gateway, Cisco Secure Email and Web Manager

ID: b26dfa4e-5f01-5d12-b6fc-7c428ac7e937

STIX ID: report--b26dfa4e-5f01-5d12-b6fc-7c428ac7e937

Feed Name: Arctic Wolf

Threat Score
90/100

Date Published: 2025-12-19

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

Cisco disclosed (17 Dec 2025) an active campaign exploiting a zero-day (CVE-2025-20393) in Cisco AsyncOS affecting Cisco Secure Email Gateway and Secure Email and Web Manager when the Spam Quarantine feature is enabled and exposed to the internet; attackers can execute commands as root and Cisco Talos observed deployment of the AquaShell backdoor, attributing the activity to a China‑affiliated actor (UAT-9686). Cisco and Arctic Wolf recommend removing public exposure of the Spam Quarantine port, applying patches when available, hardening appliances, enabling MDR integrations, and contacting Cisco TAC for compromise investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.