Cisco warned customers today of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. This yet-to-be-patched zero-day (CVE-2025-20393) affects only Cisco SEG and Cisco SEWM appliances with non-standard configurations, when the Spam Quarantine feature is enabled and exposed on the Internet. Cisco Talos, the company's threat intelligence research team, believes a Chinese threat group tracked as UAT-9686 is behind attacks abusing this security flaw to execute arbitrary commands with root and deploy AquaShell persistent backdoors, AquaTunnel and Chisel reverse SSH tunnel malware implants, and a log-clearing tool named AquaPurge. Indicators of compromise are available in this GitHub repository. AquaTunnel and other malicious tools used in these attacks have also been linked in the past with other Chinese state-backed hacking groups such as UNC5174 and APT41. "We assess with moderate confidence that the adversary, who we are tracking as UAT-9686, is a Chinese-nexus advanced persistent threat (APT) actor whose tool use and infrastructure are consistent with other Chinese threat groups," Cisco Talos said in a Wednesday advisory. "As part of this activity, UAT-9686 deploys a custom persistence mechanism we track as AquaShell accompanied by additional tooling meant for reverse tunneling and purging logs." While the company spotted these attacks on December 10, the ca...
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Dec 17, 2025
·Updated
Affected Software
2 affected components
Cisco Secure Email Gateway
Cisco Secure Email and Web Manager
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly discovered unpatched zero-day vulnerability in Cisco AsyncOS affecting specific email security appliances.
2
What security implications are discussed in the article?
The article highlights that the zero-day vulnerability is being actively exploited, posing a significant threat to Cisco Secure Email Gateway and Secure Email and Web Manager appliances.
3
What products are affected by the Cisco AsyncOS zero-day vulnerability?
The security vulnerability impacts Cisco Secure Email Gateway (SEG) and Cisco Secure Email and Web Manager (SEWM) appliances.
4
What is the CVE identifier for the zero-day vulnerability mentioned?
The zero-day vulnerability is identified as CVE-2025-20393.
5
Has a patch been released for the AsyncOS zero-day exploitation?
No, Cisco has confirmed that there is currently no patch available for the exploited zero-day vulnerability.