{"id":9946,"date":"2026-01-17T10:04:13","date_gmt":"2026-01-17T10:04:13","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/17\/cisco-0-day-rce-secure-email-gateway-vulnerability-exploited-in-the-wild\/"},"modified":"2026-01-17T10:04:13","modified_gmt":"2026-01-17T10:04:13","slug":"cisco-0-day-rce-secure-email-gateway-vulnerability-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/17\/cisco-0-day-rce-secure-email-gateway-vulnerability-exploited-in-the-wild\/","title":{"rendered":"Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild"},"content":{"rendered":"<p>    Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cisco has confirmed active exploitation of a critical zero-day remote code execution vulnerability in its Secure Email Gateway and Secure Email and Web Manager appliances. <\/p>\n<p>Tracked as <a href=\"https:\/\/cybersecuritynews.com\/tool-cisco-secure-email-gateway-0-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-20393<\/a>, the flaw allows unauthenticated attackers to execute arbitrary root-level commands via crafted HTTP requests to the Spam Quarantine feature.<\/p>\n<p>The vulnerability stems from insufficient validation of HTTP requests in the Spam Quarantine feature of Cisco AsyncOS Software, enabling remote command execution with root privileges on affected appliances.<\/p>\n<p>Classified under CWE-20 (Improper Input Validation), it scores a maximum CVSSv3.1 base of 10.0, highlighting its network accessibility, low complexity, and full impact on confidentiality, integrity, and availability.<\/p>\n<p>Exploitation targets appliances where Spam Quarantine is enabled and exposed to the internet, typically on port 6025, a configuration not enabled by default and discouraged in deployment guides.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>CVSS Score<\/th>\n<th>Vector String<\/th>\n<th>CWE ID<\/th>\n<th>Bug IDs<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-20393<\/td>\n<td>10.0<\/td>\n<td>CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H<\/td>\n<td>CWE-20<\/td>\n<td>CSCws36549, CSCws52505 <\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Cisco became aware of the attacks on December 10, 2025, with evidence of exploitation dating back to November 2025.<\/p>\n<h2 class=\"wp-block-heading\" id=\"exploitation-campaign-and-threat-actor\"><strong>Exploitation Campaign and Threat Actor<\/strong><\/h2>\n<p>Cisco Talos attributes the campaign to <a href=\"https:\/\/cybersecuritynews.com\/cisco-and-palo-alto-vpn-gateways-under-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">UAT-9686<\/a> (also UNC-9686), a China-nexus advanced persistent threat actor, with moderate confidence based on tooling overlaps with groups like APT41 and UNC5174.<\/p>\n<p>Attackers deploy a Python-based backdoor called AquaShell for persistent remote access, alongside reverse SSH tunneling tools like AquaTunnel and Chisel for internal pivoting, and AquaPurge for log wiping to evade detection. Targets include telecommunications and critical infrastructure sectors, with post-exploitation focusing on espionage rather than ransomware.<\/p>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added <a href=\"https:\/\/cybersecuritynews.com\/cisco-secure-email-devices-zero-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-20393<\/a> to its Known Exploited Vulnerabilities catalog on December 17, 2025, mandating federal agencies to mitigate by December 24, 2025. No public proof-of-concept exploits exist as of January 2026, but automated scanning has increased.<\/p>\n<p>Indicators of compromise include the implanted persistence mechanism, a covert channel for remote access; Cisco recommends verifying via Technical Assistance Center (TAC) support with remote access enabled.<\/p>\n<h2 class=\"wp-block-heading\" id=\"mitigation-and-fixed-releases\"><strong>Mitigation and Fixed Releases<\/strong><\/h2>\n<p>Cisco released <a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-sma-attack-N9bf4\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">patches<\/a> addressing the vulnerability and removing known persistence mechanisms; no workarounds exist. Administrators should upgrade immediately and confirm Spam Quarantine status via the web interface under Network &gt; IP Interfaces.<\/p>\n<p><strong>Cisco Secure Email Gateway Fixed Releases<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Vulnerable Release<\/th>\n<th>First Fixed Release<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>14.2 and earlier<\/td>\n<td>15.0.5-016<\/td>\n<\/tr>\n<tr>\n<td>15.0<\/td>\n<td>15.0.5-016<\/td>\n<\/tr>\n<tr>\n<td>15.5<\/td>\n<td>15.5.4-012<\/td>\n<\/tr>\n<tr>\n<td>16.0<\/td>\n<td>16.0.4-016<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>Cisco Secure Email and Web Manager Fixed Releases<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Vulnerable Release<\/th>\n<th>First Fixed Release<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>15.0 and earlier<\/td>\n<td>15.0.2-007<\/td>\n<\/tr>\n<tr>\n<td>15.5<\/td>\n<td>15.5.4-007<\/td>\n<\/tr>\n<tr>\n<td>16.0<\/td>\n<td>16.0.4-010<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Additional hardening includes firewalling, separating mail\/management interfaces, disabling unnecessary services such as HTTP\/FTP, and using strong <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> protocols such as SAML or LDAP.<\/p>\n<p>Cisco Secure Email Cloud services remain unaffected. Organizations should monitor logs externally and contact TAC for compromise assessment.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-0-day-rce-secure-email-gateway-vulnerability\/\">Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-0-day-rce-secure-email-gateway-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild Cisco has confirmed active exploitation of a critical zero-day remote code execution vulnerability in its Secure Email Gateway and Secure Email and Web Manager appliances. Tracked as CVE-2025-20393, the flaw allows unauthenticated attackers to execute arbitrary root-level commands via crafted HTTP requests to the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-9946","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9946"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9946"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9946\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9946"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9946"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9946"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}