Cisco has confirmed that a sophisticated cyberattack campaign is actively targeting a subset of Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances running AsyncOS Software. The attackers are exploiting a critical vulnerability, tracked as CVE-2025-20393, which allows them to execute arbitrary commands with root privileges on affected systems. Cisco's investigation has revealed that the threat actors have deployed a persistence mechanism to maintain control over compromised appliances, and there are currently no available workarounds. Customers are strongly advised to follow Cisco's mitigation guidance to assess exposure and reduce risk.
Cisco Talos has attributed this campaign to a Chinese-nexus advanced persistent threat (APT) group, tracked as UAT-9686. The attackers have deployed a custom Python-based backdoor called "AquaShell," along with additional tools for reverse tunneling and log purging, such as AquaTunnel and AquaPurge. The campaign has been ongoing since at least late November 2025 and primarily affects appliances with non-standard configurations exposed to the internet. The attack highlights the importance of securing management interfaces and promptly applying vendor-recommended mitigations to prevent further compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Following Cisco's disclosure, CISA added CVE-2025-20393 to its Known Exploited Vulnerabilities catalog, formally recognizing active exploitation. Multiple reports say federal agencies were directed to apply mitigations by December 24, 2025.
Alongside its disclosure, Cisco warned that if compromise is confirmed, affected appliances should be rebuilt because attacker persistence may survive simpler remediation. It also recommended restricting internet exposure of Spam Quarantine and tightening access controls while awaiting a fix.
Cisco publicly disclosed the critical unauthenticated remote command execution flaw CVE-2025-20393 on December 17, 2025, confirming active exploitation in Secure Email Gateway and Secure Email and Web Manager. The company issued an advisory, published indicators of compromise and mitigation guidance, and said no patch was yet available.
Cisco became aware of the campaign and identified the underlying vulnerability on December 10, 2025. Reporting indicates Cisco began investigating active exploitation of the flaw affecting exposed AsyncOS appliances at that time.
After initial compromise, the attackers installed the AquaShell Python backdoor for persistence and used AquaTunnel/ReverseSSH, chisel, and AquaPurge to tunnel access, move laterally, and purge logs. Cisco Talos later noted overlaps in tactics and infrastructure with Chinese APT activity including APT41 and UNC5174.
A China-linked threat actor tracked as UAT-9686 began exploiting the now-tracked CVE-2025-20393 against Cisco Secure Email Gateway and Secure Email and Web Manager appliances. The activity has been reported as ongoing since at least late November 2025 and targeted appliances with internet-exposed Spam Quarantine or other non-standard exposed configurations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
23 references tracked. Mallory keeps watching after this page renders.
arcticwolf.com
Open sourcearcticwolf.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcesec.cloudapps.cisco.com
Open sourceblog.talosintelligence.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.