CVE-2025-20393 could allow an attacker to execute arbitrary code with root privileges
CVE-2025-20393 could allow an attacker to execute arbitrary code with root privileges
The following platforms are known to be affected:
Cisco Secure Email and Web Manager
The following platforms are also known to be affected:
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances are vulnerable when both of the following conditions are met:
All releases of Cisco AsyncOS Software are affected by this attack campaign.
Cisco has confirmed that all devices that are part of Cisco Secure Email Cloud are not affected.
CVE-2025-20393 Under Active Exploitation
Cisco is aware of a cyberattack campaign targeting a limited subset of appliances with certain ports open to the internet that are running Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. As part of the exploitation campaign, Cisco has identified the deployment of malware including a backdoor used to maintain persistent access to the affected systems.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-20393 to their Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses future exploitation as likely.
Cisco has released a security advisory to address a critical vulnerability in Cisco's Email Security solutions formerly known as IronPort.
The vulnerability impact Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and Cisco Secure Email and Web Manager, formerly known as Cisco Content Security Management Appliance (SMA).
Affected organisations are encouraged to review Cisco's cisco-sa-sma-attack-N9bf4 security advisory to assess exposure and mitigate risks.
Cisco is aware of a potential vulnerability. Cisco is currently investigating and will update these details as appropriate as more information becomes available.
Last edited: 18 December 2025 1:29 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
