Cisco has released urgent security updates to address a critical vulnerability in its Secure Email Gateway and Secure Email and Web Manager products after confirming active exploitation by a China-linked threat group.
The flaw, tracked as CVE-2025-20393 and assigned the maximum CVSS score of 10.0, allows remote attackers to execute arbitrary commands with full root privileges. Cisco disclosed that the vulnerability had been abused as a zero-day in real-world attacks before a patch was available.
Details of the Vulnerability
The issue stems from improper validation of HTTP requests within the Spam Quarantine feature of Cisco AsyncOS Software. When exploited, the weakness enables unauthenticated attackers to remotely run system-level commands on affected appliances.
For an attack to succeed, three conditions must be present:
- The device must be running a vulnerable version of Cisco AsyncOS
- The Spam Quarantine feature must be enabled
- The feature must be accessible from the internet
Active Exploitation by Advanced Threat Actor
Cisco previously revealed evidence that a China-aligned advanced persistent threat (APT) group, tracked as UAT-9686, began exploiting the vulnerability as early as late November 2025. According to Cisco’s findings, the attackers deployed multiple tools to maintain access and evade detection.
These included tunneling utilities such as ReverseSSH (also known as AquaTunnel) and Chisel, as well as a log-wiping tool called AquaPurge. The campaign also involved a lightweight Python-based backdoor, dubbed AquaShell, capable of receiving encoded instructions and executing them on compromised systems.
Patched Versions Released
Cisco confirmed that the latest updates not only close the vulnerability but also remove persistence mechanisms planted during the attacks. The following versions contain fixes:
Cisco Secure Email Gateway
- AsyncOS 14.2 and earlier – fixed in 15.0.5-016
- AsyncOS 15.0 – fixed in 15.0.5-016
- AsyncOS 15.5 – fixed in 15.5.4-012
- AsyncOS 16.0 – fixed in 16.0.4-016
Cisco Secure Email and Web Manager
- AsyncOS 15.0 and earlier – fixed in 15.0.2-007
- AsyncOS 15.5 – fixed in 15.5.4-007
- AsyncOS 16.0 – fixed in 16.0.4-010
Security Recommendations for Customers
In addition to applying patches immediately, Cisco is urging customers to strengthen their security posture by:
- Restricting appliance access behind firewalls
- Preventing exposure to untrusted networks
- Monitoring web logs for unusual inbound or outbound traffic
- Disabling HTTP access to the main administrator interface
- Turning off unnecessary network services
- Enforcing strong authentication methods such as SAML or LDAP
- Replacing default administrator passwords with strong, unique credentials
Why It Matters
Email gateways remain a high-value target for cyber espionage groups due to their access to sensitive communications. This incident highlights the growing trend of sophisticated threat actors rapidly weaponizing zero-day flaws in widely deployed enterprise infrastructure.
Organizations using Cisco Secure Email products are strongly advised to apply updates without delay and review their configurations to reduce external exposure.