Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityperimeter-device-exposurewidely-deployed-product-advisorystate-sponsored-espionage

Cisco AsyncOS CVE-2025-20393 Zero-Day Exploited Against Secure Email Appliances

Updated 2mo agoFirst seen Jan 16, 20267 sources

Cisco released fixes for a maximum-severity vulnerability in AsyncOS (tracked as CVE-2025-20393, CVSS 10.0) affecting Cisco Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. Cisco reported the issue was exploited as a zero-day in attacks against a limited subset of internet-exposed appliances, enabling attackers to execute arbitrary commands with root privileges on the underlying operating system. The flaw was attributed to insufficient HTTP request validation in the Spam Quarantine feature, allowing crafted HTTP requests to trigger root-level command execution.

Cisco and Cisco Talos attributed the exploitation activity to UAT-9686, described as a China-linked threat group, with activity observed since at least late November 2025 and detected by Cisco on December 10. Cisco stated the intrusions included deployment of a persistence mechanism to maintain control over compromised appliances, and indicated that the released software updates both remediate the vulnerability and remove related persistence mechanisms; Cisco urged affected customers to upgrade to fixed releases per the updated advisory.

Share:
Cisco AsyncOS CVE-2025-20393 Zero-Day Exploited Against Secure Email Appliances
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 15, 20265mo ago

Cisco Talos attributes campaign to UAT-9686 and reveals tooling

With the patch release, Cisco Talos publicly attributed the intrusions to UAT-9686 and disclosed technical details of the campaign, including the use of AquaShell, AquaTunnel, AquaPurge, and Chisel. Cisco also said its investigation had found evidence of persistence on compromised appliances.

Cisco releases patches for exploited AsyncOS flaw

On January 15, 2026, Cisco released software updates for affected AsyncOS versions to fix CVE-2025-20393 in Secure Email Gateway and Secure Email and Web Manager appliances. Cisco said the updates also remove installed persistence mechanisms and urged customers to upgrade to fixed releases.

Dec 17, 20256mo ago

CISA adds CVE-2025-20393 to the KEV catalog

CISA added the actively exploited Cisco AsyncOS vulnerability to its Known Exploited Vulnerabilities catalog in December 2025. Federal agencies were directed to mitigate the issue on an accelerated timeline.

Cisco discloses CVE-2025-20393 and publishes workarounds

On December 17, 2025, Cisco publicly disclosed the maximum-severity AsyncOS vulnerability CVE-2025-20393 and issued an advisory with mitigations while a full fix was still unavailable. The company warned that the flaw was under active exploitation as a zero-day.

Dec 10, 20257mo ago

Cisco becomes aware of active attacks on CVE-2025-20393

Cisco said it first became aware on December 10, 2025 that attackers were exploiting the AsyncOS flaw in the wild. The activity included root command execution and the installation of persistence on compromised appliances.

Nov 30, 20257mo ago

UAT-9686 begins exploiting AsyncOS zero-day

Cisco Talos assessed that the China-linked threat group UAT-9686 had been exploiting CVE-2025-20393 against a limited subset of internet-exposed Cisco Secure Email Gateway and Secure Email and Web Manager appliances since at least late November 2025. The attacks targeted systems with the Spam Quarantine feature enabled and exposed.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Threat actors
1 linked
Affected products
1 linked
Cisco Secure Email Gateway
Organizations
10 linked
Cisco SystemsKeeper SecurityBlackpoint CyberAmazon Web ServicesAT&TVisaInfobloxGoogleAxurSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cisco AsyncOS CVE-2025-20393 Zero-Day Exploited Against Secure Email Appliances | Mallory