ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Patches Zero-Day RCE Exploited by China

criticalExploit / PoCimportance 60CVE-2025-20393

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20393
Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands

CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined.

Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown.

10.030% KEV
  • Cisco Secure Email Gateway / Secure Email
  • Cisco AsyncOS Software
  • Cisco Web Manager appliance
largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished)
Full article416 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 16, 2026Vulnerability / Web Security

Cisco on Thursday released security updates for a maximum-severity security flaw impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, nearly a month after the company disclosed that it had been exploited as a zero-day by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686.

The vulnerability, tracked as CVE-2025-20393 (CVSS score: 10.0), is a remote command execution flaw arising as a result of insufficient validation of HTTP requests by the Spam Quarantine feature. Successful exploitation of the defect could permit an attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.

However, for the attack to work, three conditions must be met -

  • The appliance is running a vulnerable release of Cisco AsyncOS Software
  • The appliance is configured with the Spam Quarantine feature
  • The Spam Quarantine feature is exposed to and reachable from the internet

Last month, the networking equipment major revealed that it found evidence of UAT-9686 exploiting the vulnerability as early as late November 2025 to drop tunneling tools like ReverseSSH (aka AquaTunnel) and Chisel, and a log cleaning utility called AquaPurge.

The attacks are also characterized by the deployment of a lightweight Python backdoor dubbed AquaShell that's capable of receiving encoded commands and executing them.

The vulnerability has now been addressed in the following versions, in addition to removing the persistence mechanisms that were identified in this attack campaign and installed on the appliances -

Cisco Email Security Gateway

  • Cisco AsyncOS Software Release 14.2 and earlier (Fixed in 15.0.5-016)
  • Cisco AsyncOS Software Release 15.0 (Fixed in 15.0.5-016)
  • Cisco AsyncOS Software Release 15.5 (Fixed in 15.5.4-012)
  • Cisco AsyncOS Software Release 16.0 (Fixed in 16.0.4-016)

Secure Email and Web Manager

  • Cisco AsyncOS Software Release 15.0 and earlier (Fixed in 15.0.2-007)
  • Cisco AsyncOS Software Release 15.5 (Fixed in 15.5.4-007)
  • Cisco AsyncOS Software Release 16.0 (Fixed in 16.0.4-010)

Additionally, Cisco is also urging customers to follow hardening guidelines to prevent access from the unsecured networks, secure the appliances behind a firewall, monitor web log traffic for any unexpected traffic to/from appliances, disable HTTP for the main administrator portal, disable any network services that are not required, enforce a strong form of end-user authentication to the appliances (e.g., SAML or LDAP), and change the default administrator password to a more secure variant.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/01/cisco-patches-zero-day-rce-exploited-by.html