A critical vulnerability, tracked as CVE-2025-20393, has been identified in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager products running any version of AsyncOS with the Spam Quarantine feature enabled and exposed to the internet. Cisco released a security advisory detailing the flaw and urging administrators to review recommendations and apply necessary updates to mitigate the risk. The vulnerability allows for improper input validation, which could be exploited by malicious actors to compromise affected systems.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-20393 to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. Federal agencies are required to remediate this vulnerability by the specified deadline, and CISA strongly encourages all organizations to prioritize patching to reduce exposure to cyberattacks. The inclusion of this vulnerability in the KEV Catalog highlights its significance as a frequent attack vector and underscores the urgent need for remediation across both public and private sectors.

See which actors are running it and whether you're in range.
9 events from the most recent confirmed update back to the earliest known activity.
Published on 2026-02-05, STAR Labs described CVE-2025-20393 as stemming from a single-byte integer overflow in the EUQ RPC protocol that could bypass authentication checks and feed attacker-controlled data into cPickle.loads() for unauthenticated remote code execution. The write-up also said Cisco addressed the flaw in AsyncOS 15.5.4 by rejecting source or destination length values of 255 bytes or greater.
By 2025-12-21, reporting indicated that at least 120 Cisco Secure Email Gateway and Secure Email and Web Manager devices were confirmed vulnerable and exposed while no official patch was yet available. The update showed the scale of internet-facing exposure and the continuing risk from active exploitation.
On 2025-12-19, a Python tool called 'Cisco SMA Exposure Check' was released to help organizations identify internet-exposed systems and possible indicators of compromise related to CVE-2025-20393. The script checks open ports, fingerprints HTTP/S services, and looks for artifacts associated with post-compromise tooling such as AquaShell and Chisel.
On 2025-12-18, CERT-EU issued an advisory warning that CVE-2025-20393 could allow arbitrary commands with root privileges on exposed appliances. It urged defenders to verify exposure, restrict access, and investigate for lateral movement or compromise.
By 2025-12-18, public reporting attributed exploitation of CVE-2025-20393 to a China-linked APT, identified as UAT-9686 with overlaps to UNC5174 and APT41. This represented an attribution update beyond the initial vendor disclosure of active exploitation.
Cisco's investigation, referenced in later reporting, said the attack activity was first identified through a Cisco TAC case and further analyzed by Cisco Talos. The analysis found attackers implanting persistence, disabling security tools, and establishing covert channels on compromised appliances.
On 2025-12-17, CISA added CVE-2025-20393 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The addition triggered remediation requirements for U.S. Federal Civilian Executive Branch agencies under Binding Operational Directive 22-01.
At disclosure, Cisco said no patch was available for CVE-2025-20393 and advised organizations to restrict or remove internet exposure of the vulnerable Spam Quarantine interface, investigate for compromise, and rebuild affected appliances if necessary. Multiple advisories noted Cisco Secure Email Cloud was not affected.
On 2025-12-17, Cisco disclosed a critical vulnerability, CVE-2025-20393, affecting Secure Email Gateway and Secure Email and Web Manager appliances running AsyncOS when the Spam Quarantine feature is enabled and exposed to the internet. The flaw allows unauthenticated remote command execution as root and was reported as actively exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
11 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcethecyberexpress.com
Open sourcecyber.gc.ca
Open sourcerunzero.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.