CVE-2025-20393: Threat Campaign Targeting Cisco Secure Email Gateway, Cisco Secure Email and Web Manager
ID: b26dfa4e-5f01-5d12-b6fc-7c428ac7e937
STIX ID: report--b26dfa4e-5f01-5d12-b6fc-7c428ac7e937
Feed Name: Arctic Wolf
Cisco disclosed (17 Dec 2025) an active campaign exploiting a zero-day (CVE-2025-20393) in Cisco AsyncOS affecting Cisco Secure Email Gateway and Secure Email and Web Manager when the Spam Quarantine feature is enabled and exposed to the internet; attackers can execute commands as root and Cisco Talos observed deployment of the AquaShell backdoor, attributing the activity to a China‑affiliated actor (UAT-9686). Cisco and Arctic Wolf recommend removing public exposure of the Spam Quarantine port, applying patches when available, hardening appliances, enabling MDR integrations, and contacting Cisco TAC for compromise investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
