logo

Cisco Secure Email Gateway Zero-Day RCE Exploited in Active Attacks

ID: aba66205-c0ee-57d8-8fbf-6c03ae51b98d

STIX ID: report--aba66205-c0ee-57d8-8fbf-6c03ae51b98d

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-16

Date Updated: 2026-04-22

Author: Divya

...
...

Cisco confirmed an active campaign exploiting CVE-2025-20393, a critical (CVSS 10.0) vulnerability in AsyncOS Spam Quarantine that permits unauthenticated remote command execution as root on Secure Email Gateway and Secure Email and Web Manager appliances; attackers have installed persistent backdoors. Cisco released patched AsyncOS versions and strongly urges immediate upgrades, verification of Spam Quarantine status, and restricting appliance access because no workarounds exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.