Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20393 | Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined. Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown. | 10.0 | 30% | KEV |
| largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished) |
Full article369 words · extracted from helpnetsecurity.com · click to collapse
Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exploited as a zero-day by suspected Chinese attackers since at least late November 2025.
The company revealed the flaw’s existence and in-the-wild exploitation on December 17, 2025, and urged customers to check whether their appliances had been breached and to rebuild them in case of confirmed compromise.
CVE-2025-20393 exploitation
“[CVE-2025-20393] is due to insufficient validation of HTTP requests by the Spam Quarantine feature. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device,” Cisco explained.
“This attack allows the [unauthenticated] threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.”
Cisco Talos researchers found that attackers installed on “a limited subset of appliances” a custom-made Python backdoor (AquaShell), a log-purging tool (AquaPurge), a reverse SSH backdoor (AquaTunnel), and an open‑source tunneling tool used for proxying traffic (Chisel).
The attackers were able to compromise only appliances that had the Spam Quarantine feature enabled and reachable from the internet.
Cisco still hasn’t disclosed how many systems were affected, though it stressed that the Spam Quarantine feature is not enabled by default.
Fixes finally available
In December, the US Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered US federal civilian agencies to address CVE-2025-20393 using Cisco-provided mitigations.
Now, those agencies – and other Cisco customers – must apply the newly released security updates.
Cisco Email Security Gateway appliances should be upgraded to AsyncOS v15.0.5-016 or later, 15.5.4-012 or later, or 16.0.4-016 or later.
Secure Email and Web Manager devices should be upgraded to AsyncOS v15.0.2-007 or later, 15.5.4-007 or later, or 16.0.4-010 or later.
The devices will automatically reboot after the upgrade.
“The fix addresses the vulnerability used by threat actors and clears the persistence mechanisms that were identified in this attack campaign and installed on the appliances,” Cisco added, and advised organizations to additionally harden their devices.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/01/16/cisco-fixes-asyncos-vulnerability-exploited-in-zero-day-attacks-cve-2025-20393/