Cisco Patches AsyncOS Zero-Day Vulnerability Exploited Since November 2025
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Cisco has addressed a maximum-severity vulnerability in its AsyncOS software, specifically affecting its Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. This vulnerability, tracked as CVE-2025-20393, has been exploited in attacks since November 2025. The flaw arises from improper input validation, allowing threat actors to execute arbitrary commands with root privileges on affected appliances.
The vulnerability primarily impacts Cisco SEG and SEWM appliances that have non-standard configurations, particularly when the Spam Quarantine feature is enabled and exposed to the Internet. Cisco disclosed this issue in December 2025, prompting immediate attention from organizations using these appliances.
Cisco Talos, the company’s threat intelligence team, has linked the exploitation of this vulnerability to a Chinese hacking group identified as UAT-9686. This group has been observed deploying various malicious tools, including AquaShell persistent backdoors, AquaTunnel, and Chisel reverse-SSH tunnel malware, as well as AquaPurge, a log-clearing tool.
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-20393 to its catalog of known exploited vulnerabilities on December 17, 2025. CISA mandated that federal agencies secure their systems using Cisco’s guidance by December 24, 2025, as part of Binding Operational Directive 22-01.
This incident highlights the significant risks posed by such vulnerabilities, especially when they are actively exploited by advanced persistent threat (APT) actors. Organizations using Cisco SEG and SEWM appliances should take immediate action to mitigate risks associated with this vulnerability.
Implications for Organizations
Organizations using Cisco SEG and SEWM appliances must prioritize upgrading to the fixed software version provided by Cisco. The presence of vulnerabilities like CVE-2025-20393 can lead to unauthorized access and potential data breaches, making it crucial for organizations to assess their exposure.
Monitoring for signs of compromise is essential, particularly for internet-accessible Cisco products affected by this vulnerability. Organizations should implement additional security measures, such as network segmentation and regular security audits, to reduce the risk of exploitation.
Key Takeaways
- Upgrade your Cisco SEG and SEWM appliances to the latest fixed software version as soon as possible.
- Monitor for signs of compromise on all internet-accessible Cisco products affected by CVE-2025-20393.
- Review and adjust configurations to ensure that the Spam Quarantine feature is not unnecessarily exposed to the Internet.
- Implement network segmentation to limit access to critical systems and reduce potential attack surfaces.
- Conduct regular security audits to identify and address vulnerabilities in your systems.
Key Terms & Concepts
- CVE-2025-20393: In this article, CVE-2025-20393 refers to a critical vulnerability in Cisco’s AsyncOS software that allows arbitrary command execution.
- UAT-9686: UAT-9686 is a Chinese hacking group identified by Cisco Talos as likely exploiting the AsyncOS vulnerability.
- AquaShell: AquaShell is a persistent backdoor used by threat actors to maintain access to compromised systems.
- AquaTunnel: AquaTunnel is a reverse-SSH tunnel malware implant deployed by attackers to facilitate unauthorized access.
- CISA: CISA stands for the Cybersecurity and Infrastructure Security Agency, which oversees cybersecurity efforts in the U.S.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.