Cisco Patches Actively Exploited AsyncOS Zero-Day in Email Security Appliances

Cisco has fixed a serious zero-day flaw (CVE-2025-20393) in its AsyncOS software that attackers have been actively exploiting since November. The bug allows unauthenticated remote attackers to take full control of affected email security appliances.

The vulnerable systems sit in a high-trust position on corporate networks, so a successful compromise could let attackers spy on email traffic, move laterally, or maintain long-term access.


Who is affected

The issue impacts:

  • Cisco Email Security Gateway (SEG) appliances
  • Secure Email and Web Manager (SEWM) appliances

Exploitation mainly targeted systems where the Spam Quarantine feature was enabled and exposed to the internet.


Email Security Gateway appliances must be upgraded to:

  • AsyncOS 15.0.5-016 or later
  • AsyncOS 15.5.4-012 or later
  • AsyncOS 16.0.4-016 or later

Secure Email and Web Manager appliances must be upgraded to:

  • AsyncOS 15.0.2-007 or later
  • AsyncOS 15.5.4-007 or later
  • AsyncOS 16.0.4-010 or later

There are no workarounds. If you don’t upgrade, the device remains vulnerable.


Important: patching alone may not be enough

If your appliance was internet-exposed at any point since November, you should assume it may have been compromised, even after upgrading.

Cisco confirmed attackers used:

  • A Python-based backdoor
  • Persistence mechanisms
  • Log-clearing techniques to hide activity

Because of this:

  • Review the system for unusual users, files, or outbound connections
  • Rotate admin and service credentials
  • Consider contacting Cisco TAC for validation
  • In high-risk environments, a full rebuild from a clean image may be the safest option

How to reduce risk going forward

  • Do not expose Spam Quarantine or admin interfaces to the internet
  • Restrict access using internal networks, VPNs, or IP allowlists
  • Segment management interfaces from user networks
  • Keep optional features disabled unless absolutely needed
  • Apply AsyncOS updates promptly going forward

Bottom line

This was a maximum-severity vulnerability, exploited in the wild for weeks. If you run Cisco email security appliances and haven’t upgraded yet, you are urgently at risk. Patch immediately, then verify that the system hasn’t already been compromised.