Cisco Secure Email Gateway Zero-Day RCE Exploited in Active Attacks
ID: aba66205-c0ee-57d8-8fbf-6c03ae51b98d
STIX ID: report--aba66205-c0ee-57d8-8fbf-6c03ae51b98d
Feed Name: GBHackers
Threat Score
Cisco confirmed an active campaign exploiting CVE-2025-20393, a critical (CVSS 10.0) vulnerability in AsyncOS Spam Quarantine that permits unauthenticated remote command execution as root on Secure Email Gateway and Secure Email and Web Manager appliances; attackers have installed persistent backdoors. Cisco released patched AsyncOS versions and strongly urges immediate upgrades, verification of Spam Quarantine status, and restricting appliance access because no workarounds exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
