Cisco Warns of Active Cyberattack Exploiting Critical AsyncOS Vulnerability
18 December 2025 at 04:11
![]()
Attack Detection and Timeline
The cyberattack was initially identified through a routine Cisco Technical Assistance Center (TAC) case. Following the discovery, Cisco Talos documented the threat in a blog post, noting the active targeting of Cisco Secure Email Gateway and Web Manager appliances. Evidence suggests that attackers leveraged exposed ports to gain unauthorized root access, disable security tools, and establish covert channels for ongoing remote access. Administrators can check whether the Spam Quarantine feature is enabled by accessing the appliance's web management interface:- For Cisco Secure Email Gateway: Navigate to Network > IP Interfaces and select the interface configured for Spam Quarantine.
- For Cisco Secure Email and Web Manager: Navigate to Management Appliance > Network > IP Interfaces and select the relevant interface.
No Direct Workarounds for CVE-2025-20393
Cisco has stated that no immediate workarounds exist to fully mitigate the risk of cyberattacks. Organizations are strongly urged to follow recommended mitigation steps to restore appliances to a secure configuration. If an appliance is suspected of compromise, Cisco recommends opening a TAC case and, in confirmed cases, rebuilding the appliance to eliminate the threat actors’ persistence mechanisms. Additional security hardening recommendations include:- Restricting appliance access to known, trusted hosts and avoiding direct exposure to the internet.
- Deploying appliances behind firewalls and filtering traffic to allow only authorized communication.
- Separating mail and management network interfaces for Cisco Secure Email Gateway to limit internal access risk.
- Regularly monitoring web logs and sending logs to external servers for post-event analysis.
- Disabling unnecessary network services such as HTTP and FTP and using SSL/TLS with certificates from trusted authorities.
- Upgrading appliances to the latest Cisco AsyncOS Software release.
- Implementing strong authentication methods like SAML or LDAP and creating dedicated administrator and operator accounts with passwords.