Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitystate-sponsored-espionageembedded-device-vulnerabilitypersistence-method

Targeted Exploitation of Cisco Secure Email Gateway and Web Manager by UAT-9686

Updated 3mo agoFirst seen Dec 17, 202523 sources

Cisco has confirmed that a sophisticated cyberattack campaign is actively targeting a subset of Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances running AsyncOS Software. The attackers are exploiting a critical vulnerability, tracked as CVE-2025-20393, which allows them to execute arbitrary commands with root privileges on affected systems. Cisco's investigation has revealed that the threat actors have deployed a persistence mechanism to maintain control over compromised appliances, and there are currently no available workarounds. Customers are strongly advised to follow Cisco's mitigation guidance to assess exposure and reduce risk.

Cisco Talos has attributed this campaign to a Chinese-nexus advanced persistent threat (APT) group, tracked as UAT-9686. The attackers have deployed a custom Python-based backdoor called "AquaShell," along with additional tools for reverse tunneling and log purging, such as AquaTunnel and AquaPurge. The campaign has been ongoing since at least late November 2025 and primarily affects appliances with non-standard configurations exposed to the internet. The attack highlights the importance of securing management interfaces and promptly applying vendor-recommended mitigations to prevent further compromise.

Share:
Targeted Exploitation of Cisco Secure Email Gateway and Web Manager by UAT-9686
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Dec 17, 20256mo ago

CISA adds CVE-2025-20393 to the KEV catalog

Following Cisco's disclosure, CISA added CVE-2025-20393 to its Known Exploited Vulnerabilities catalog, formally recognizing active exploitation. Multiple reports say federal agencies were directed to apply mitigations by December 24, 2025.

Cisco advises rebuilding compromised appliances

Alongside its disclosure, Cisco warned that if compromise is confirmed, affected appliances should be rebuilt because attacker persistence may survive simpler remediation. It also recommended restricting internet exposure of Spam Quarantine and tightening access controls while awaiting a fix.

Cisco discloses CVE-2025-20393 and issues security advisory

Cisco publicly disclosed the critical unauthenticated remote command execution flaw CVE-2025-20393 on December 17, 2025, confirming active exploitation in Secure Email Gateway and Secure Email and Web Manager. The company issued an advisory, published indicators of compromise and mitigation guidance, and said no patch was yet available.

Dec 10, 20257mo ago

Cisco identifies the threat campaign and vulnerability

Cisco became aware of the campaign and identified the underlying vulnerability on December 10, 2025. Reporting indicates Cisco began investigating active exploitation of the flaw affecting exposed AsyncOS appliances at that time.

Nov 30, 20257mo ago

Attackers deploy AquaShell and related post-compromise tooling

After initial compromise, the attackers installed the AquaShell Python backdoor for persistence and used AquaTunnel/ReverseSSH, chisel, and AquaPurge to tunnel access, move laterally, and purge logs. Cisco Talos later noted overlaps in tactics and infrastructure with Chinese APT activity including APT41 and UNC5174.

UAT-9686 begins exploiting Cisco AsyncOS zero-day

A China-linked threat actor tracked as UAT-9686 began exploiting the now-tracked CVE-2025-20393 against Cisco Secure Email Gateway and Secure Email and Web Manager appliances. The activity has been reported as ongoing since at least late November 2025 and targeted appliances with internet-exposed Spam Quarantine or other non-standard exposed configurations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

30 LINKEDOpen in app
Affected products
1 linked
Cisco Secure Email Gateway
Organizations
19 linked
Cisco SystemsUAT-9686CISAArctic WolfAPT41UNC5174IvantiMicrosoft CorporationTrend MicroGreyNoisefbiRapid7Palo Alto NetworksFortinetCitrix SystemsSoundcloudSonicwallHFS ResearchConfidis
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.