NewsSecurity Vulnerabilities

Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager

On December 10th 2025 Cisco became aware of a new cyberattack campaign targeting a limited subset of appliances with certain ports open to the internet that are running Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager.

This attack allows the threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. The ongoing investigation has revealed evidence of a persistence mechanism implanted by the threat actors to maintain a degree of control over compromised appliances.

Cisco has remediated the vulnerability that was exploited by the threat actors as part of the cyberattack campaign. 

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This attack campaign targets Cisco Secure Email Gateway, both physical and virtual, and Cisco Secure Email and Web Manager appliances, both physical and virtual, when all the following conditions are met:

  • The appliance is running a vulnerable release of Cisco AsyncOS Software.
  • The appliance is configured with the Spam Quarantine feature.
  • The Spam Quarantine feature is exposed to and reachable from the internet.

Vulnerable Products

The vulnerability exploited by the threat actors affects Cisco Secure Email Gateway, both physical and virtual, and Cisco Secure Email and Web Manager appliances, both physical and virtual, when the appliance is configured with the Spam Quarantine feature, which is not enabled by default. Deployment guides for these products do not require this feature to be directly exposed to the Internet.

The assigned CVE is CVE-2025-20393

Cisco Talos wrote about these attacks in the blog post UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.