Cisco AsyncOS RCE added to CISA KEV, no patch available
Active exploitation confirmed, and the only remediation is an appliance rebuild, a worst-case scenario for email gateway operators running Spam Quarantine facing the internet.
TL;DR
CISA added CVE-2025-20393 (an unauthenticated RCE in Cisco AsyncOS) to its Known Exploited Vulnerabilities catalog on December 18, 2025, after Cisco confirmed active exploitation. The vulnerability affects Secure Email Gateway and Secure Email and Web Manager appliances with Spam Quarantine exposed to the internet. Cisco has not released a patch. There is no workaround: compromised appliances must be rebuilt to eradicate the persistence mechanism Cisco found attackers planting on affected systems.
The sequence is about as bad as vulnerability disclosure gets: maximum severity, active in-the-wild exploitation, a confirmed persistence mechanism, and no patch. CVE-2025-20393 landed in CISA's KEV catalog Thursday, and the agencies and contractors running Cisco Secure Email Gateway appliances are now in the highest-friction remediation scenario available, rebuild or remain exposed.
Cisco became aware of the attack campaign on December 10, targeting what it calls a "limited subset" of appliances with Spam Quarantine reachable from the internet. Spam Quarantine isn't on by default, but the deployment pattern that turns it on and leaves the port internet-facing is common enough in real-world configurations that the advisory treats exposure as a live operational risk, not a theoretical one. Threat actors are exploiting the flaw to execute arbitrary commands with root privileges, and Cisco's investigation turned up evidence of a persistence mechanism, meaning a compromised appliance can't be trusted even after you close the port.
The affected product line covers Cisco Secure Email Gateway (the ESA family) and Secure Email and Web Manager, all running AsyncOS. If your appliance has the Spam Quarantine port reachable from the internet and you haven't verified it's clean, Cisco's guidance is stark: contact TAC for a compromise assessment, and if compromised, rebuild the appliance. That's the entire remediation menu right now.
What the "no patch" gap means
No-patch vulnerabilities in KEV aren't unprecedented, but they're rare enough that each one carries disproportionate operational weight. CISA's Binding Operational Directive 22-01 applies to federal civilian agencies, with remediation timelines that start when a patch is available. Until Cisco ships one, the BOD clock isn't formally ticking, but the attacker's is. For contractors and subcontractors under CMMC or DFARS 7012, the calculus is different: the requirement to protect CUI doesn't pause because Cisco hasn't shipped a fix. If a compromised email gateway sits in the flow of covered defense information, the exposure is active and the clock is running on incident reporting obligations.
What the practitioner does Monday
First, verify whether Spam Quarantine is enabled and internet-facing on every Secure Email Gateway and Web Manager appliance. This isn't a scan-and-forget check, confirm the configuration state directly on the appliance. If exposure is confirmed and you can't verify cleanliness, Cisco's recommendation to rebuild is the only path that addresses the persistence risk. If your organization runs these appliances in a regulated environment, document the configuration check, the results, and any remediation decisions now, before the patch arrives and the BOD timeline starts compressing everyone's decision window.
Published ·Deep Fathom