Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Cisco Fixes Zero-Day RCE Actively Exploited in Secure Email Gateways

2151883592

Cisco Fixes Zero-Day RCE Actively Exploited in Secure Email Gateways

Cisco Systems has released security updates addressing a maximum-severity vulnerability affecting Cisco Secure Email Gateway and Secure Email and Web Manager appliances.
The flaw was previously exploited as a zero-day by a China-linked advanced persistent threat (APT), highlighting the continued targeting of email security infrastructure as a high-value entry point.

What happened

The vulnerability, tracked as CVE-2025-20393 with a CVSS score of 10.0, allows remote command execution due to insufficient validation of HTTP requests in the Spam Quarantine feature.

When successfully exploited, the issue enables attackers to execute arbitrary commands with root-level privileges on the affected appliance, effectively granting full system control.

Conditions required for exploitation

The attack is only possible when all three conditions are met:

  • The appliance runs a vulnerable version of Cisco AsyncOS

  • The Spam Quarantine feature is enabled

  • The Spam Quarantine interface is exposed to the internet

This combination is commonly observed in environments where email gateways are directly reachable for operational or administrative convenience.

Exploitation activity

Cisco confirmed that the vulnerability was exploited in the wild starting in late November 2025.
The observed activity included:

  • Deployment of tunneling utilities to establish persistent access

  • Use of lightweight backdoors capable of executing encoded commands

  • Log-cleaning mechanisms designed to reduce forensic visibility

These behaviors are consistent with long-term access operations rather than short-lived exploitation.

Affected products and fixed versions

Cisco Secure Email Gateway

  • AsyncOS 14.2 and earlier . Fixed in 15.0.5-016

  • AsyncOS 15.0 . Fixed in 15.0.5-016

  • AsyncOS 15.5 . Fixed in 15.5.4-012

  • AsyncOS 16.0 . Fixed in 16.0.4-016

Secure Email and Web Manager

  • AsyncOS 15.0 and earlier . Fixed in 15.0.2-007

  • AsyncOS 15.5 . Fixed in 15.5.4-007

  • AsyncOS 16.0 . Fixed in 16.0.4-010

Mitigation guidance

In addition to patching, Cisco recommends:

  • Restricting administrative access behind firewalls

  • Monitoring web and system logs for unexpected traffic patterns

  • Disabling unnecessary network services

  • Enforcing strong authentication mechanisms (e.g., SAML, LDAP)

  • Securing or disabling HTTP-based administrative interfaces

The DIAMATIX Perspective

From an operational standpoint, this incident reinforces a recurring pattern.
Email gateways are not just filtering tools. They are perimeter systems with direct impact on trust, access, and visibility.

Key observations:

  • Zero-day exploitation often targets availability and control, not immediate data exfiltration

  • Perimeter appliances frequently lack the same behavioral monitoring applied to endpoints

  • Root-level access to security infrastructure creates blind spots that delay detection

In real environments, compromise of an email gateway can:

  • Undermine user trust in internal communications

  • Serve as a staging point for lateral movement

  • Obscure visibility into phishing and credential abuse campaigns

This is why continuous monitoring of perimeter services, exposure management, and behavioral anomaly detection are essential parts of modern security operations.

Conclusion

This incident is a reminder that security infrastructure itself must be treated as a high-risk asset.
Timely patching, reduced exposure, and operational visibility remain critical to preventing silent, long-term compromise.

Disclosure timeline

  • Late November 2025 – Initial exploitation activity observed in the wild

  • December 2025 – Vendor investigation confirms abuse of a previously unknown vulnerability

  • January 16, 2026 – Security updates released for affected Cisco Secure Email Gateway components

  • Post-disclosure – Additional hardening and mitigation guidance published

Contact DIAMATIX

Trusted · Innovative · Vigilant


Sources

  • Cisco Security Advisory for CVE-2025-20393

  • Public CVE records and CVSS scoring (NVD / MITRE)

  • Cisco incident disclosure on active exploitation of Secure Email Gateway

  • Independent threat research on China-linked APT activity targeting email infrastructure

  • Analysis of post-exploitation tooling observed in email gateway compromises

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.