Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cisco’s CVE-2025-20393 campaign targeted a limited subset of internet-exposed Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances—not Cisco equipment generally. The risk applies when a device runs a vulnerable AsyncOS release, Spam Quarantine is enabled, and that feature is reachable from the internet. Cisco says attackers could run commands as root and implant persistence; affected administrators should check exposure, upgrade to the applicable fixed release, and contact Cisco TAC if compromise is possible.

What happened in the Cisco AsyncOS campaign?

Cisco says it became aware of the campaign on December 10, 2025. The vulnerability, CVE-2025-20393, is an insufficient HTTP request validation issue in the Spam Quarantine feature of AsyncOS. Cisco assigned it a CVSS base score of 10.0. Attackers could execute arbitrary commands with root privileges, and Cisco’s investigation found an implanted persistence mechanism intended to maintain remote control. Cisco says its software updates remediate the vulnerability and clear the persistence mechanisms it identified.

The Cisco Product Security Incident Response Team states: “There are no workarounds that address this vulnerability.” Reducing network exposure is still prudent, but it does not replace upgrading. See Cisco’s CVE-2025-20393 advisory, first published December 17, 2025 and last updated January 15, 2026.

Which Cisco appliances are affected?

The advisory covers physical and virtual Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances running a vulnerable AsyncOS release, with Spam Quarantine configured and enabled and the feature reachable from the internet. Cisco says Spam Quarantine is not enabled by default. Cisco Secure Email Cloud devices are not affected by this advisory, and Cisco said it was not aware of exploitation against Cisco Secure Web.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

All of the listed conditions matter. Identify the product family and AsyncOS branch, then confirm both whether Spam Quarantine is enabled and whether it can be reached from the internet. A device being a Cisco email appliance alone does not establish that it is affected.

How to check whether Spam Quarantine is enabled

  1. For Secure Email Gateway: In the web management interface, go to Network > IP Interfaces and inspect the relevant interface.
  2. For Secure Email and Web Manager: Go to Management Appliance > Network > IP Interfaces and inspect the relevant interface.
  3. Determine whether Spam Quarantine is enabled and whether the feature is exposed to the internet. Confirm the appliance’s exact AsyncOS release and branch; those details determine which fixed release applies.

An enabled feature is not, by itself, proof of internet exposure or compromise. If you cannot establish reachability or are unsure whether the appliance was accessed, involve your security team and Cisco TAC.

Which AsyncOS releases does Cisco list as fixed?

The following versions are the fixed releases listed in Cisco’s January 15, 2026 advisory revision. They are not a claim that no later release is available. Check the live advisory and Cisco compatibility guidance for the exact product and branch before upgrading.

Product AsyncOS branch Fixed release listed by Cisco
Secure Email Gateway 15.0 and earlier 15.0.5-016
Secure Email Gateway 15.5 15.5.4-012
Secure Email Gateway 16.0 16.0.4-016
Secure Email and Web Manager 15.0 and earlier 15.0.2-007
Secure Email and Web Manager 15.5 15.5.4-007
Secure Email and Web Manager 16.0 16.0.4-010

Do not select a release based only on the branch number: the Gateway and Manager have different fixed builds. Cisco’s advisory is the source for the applicable release and current upgrade guidance.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should administrators do now?

  1. Confirm scope: Record the appliance family, physical or virtual deployment, AsyncOS version and branch, Spam Quarantine status, and internet reachability.
  2. Upgrade: Follow Cisco’s live advisory and compatibility guidance to install the fixed release for that product and branch. Cisco says the update clears persistence mechanisms identified in this campaign.
  3. Restrict access: Limit appliance access from unsecured networks. Where access is needed, allow only known trusted hosts on necessary ports and protocols; place appliances behind a filtering device.
  4. Review network design and services: Separate mail and management interfaces where applicable, disable unnecessary services, and disable HTTP for the main administrator portal as Cisco recommends.
  5. Preserve and review logs: Monitor web logs and retain them externally when possible, so they remain available for investigation.
  6. Ask Cisco TAC to assess possible compromise: Cisco advises customers seeking confirmation to open a TAC case and enable remote access on affected appliances to expedite analysis. Follow your organization’s incident-response and access-control procedures when enabling it.

These access controls reduce exposure but are not a direct workaround for CVE-2025-20393. Cisco says no workaround directly mitigates the vulnerability.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about attribution and the campaign’s boundaries?

CyberScoop reported that Cisco Talos attributed the activity to UAT-9686 and described tooling and infrastructure as consistent with other China state-sponsored groups, including APT41 and UNC5174. This is an attribution reported by CyberScoop from Cisco Talos, not independently established identity or proof of state direction. CyberScoop also reported Cisco’s statement that it had no evidence connecting the AsyncOS attacks to the earlier Cisco firewall campaign. Treat those incidents as separate unless evidence changes.

Cisco’s advisory does not publish a victim count. CyberScoop reported that Cisco declined to provide the number of impacted customers at the time. A separate October 7, 2026 Cisco advisory concerns an NX-OS NX-API remote-code-execution vulnerability; it is a different issue and does not establish a new wave in this AsyncOS campaign: Cisco NX-OS advisory.

Quick Recap

Bestseller No. 4
Cisco Designed Meraki MX64 Cloud Managed Security Appliance, White (MX64-HW)
Cisco Designed Meraki MX64 Cloud Managed Security Appliance, White (MX64-HW)
Product Type: Networking Device; Package Quantity: 1; Package Dimensions: 7.2 cms (L) x 23.2 cms (W) x 30.8 cms (H)
$130.00
Bestseller No. 5
Cisco 3000 Network Security/Firewall Appliance
Cisco 3000 Network Security/Firewall Appliance
2 X 10/100/1000 + 2 X GIGABIT SFP; CHASIS 64 GB MSATA; DC POWER; DIN RAIL MOUNTABLE; INDUSTRIAL SECURITY APPLIANCE
$3,600.00
Best Value
Cisco 3000 Network Security/Firewall Appliance
  • 2 X 10/100/1000 + 2 X GIGABIT SFP
  • CHASIS 64 GB MSATA
  • DC POWER
  • DIN RAIL MOUNTABLE
  • INDUSTRIAL SECURITY APPLIANCE
Rank #4
Cisco Designed Meraki MX64 Cloud Managed Security Appliance, White (MX64-HW)
  • Product Type: Networking Device
  • Package Quantity: 1
  • Package Dimensions: 7.2 cms (L) x 23.2 cms (W) x 30.8 cms (H)
  • Country Of Origin: China

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.