Threat reportVulnerabilityTL-2026-1541
CVE-2025-20393 — Cisco Secure Email Gateway RPC Integer Overflow Enabling Auth Bypass and Unsafe Pickle Deserialization (CVSS 10.0), Exploited by China-Nexus APT UAT-9686
CVE-2025-20393 (TL-2026-1541), also tracked as Pickling the Mailbox, is a critical-severity software vulnerability scored CVSS 10, first published 2026-02-05. It is attributed to UAT-9686 (China) with medium confidence, affects Cisco Secure Email Gateway (formerly Email Security Appliance / ESA), references 1 CVE (CVE-2025-20393), maps to 18 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 17 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 18MITRE ATT&CK
- Actors
- 1UAT-9686
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-1541
- Threat ID
- TL-2026-1541
- Also known as
- Pickling the Mailbox, AsyncOS EUQ RPC Integer Overflow
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- UAT-9686
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- government administration, technology, critical-infrastructure, telecoms
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in CVE-2025-20393
Malware and tooling: AquaPurge, AquaShell, AquaTunnel, Chisel, ReverseSSH
How CVE-2025-20393 works
A single-byte integer overflow in the EUQ RPC message header of Cisco AsyncOS Software (Secure Email Gateway / Secure Email and Web Manager) lets an unauthenticated remote attacker bypass serial-number authentication and trigger unsafe cPickle deserialization for arbitrary command execution as root. Cisco confirmed active exploitation since late November 2025 by China-nexus actor UAT-9686, which deployed the AquaShell Python backdoor, AquaTunnel (ReverseSSH-derived) and Chisel tunnels, and the AquaPurge log-cleaning utility.
CVE-2025-20393 affects the Spam Quarantine / End User Quarantine (EUQ) RPC service (TCP port 83, quarantine web UI commonly on port 6025) shipped in Cisco AsyncOS Software for Secure Email Gateway (formerly Email Security Appliance) and Secure Email and Web Manager (formerly Content Security Management Appliance). The EUQ RPC wire format uses the struct layout '>BBIIBB32s' (version, ttl, msg_len, msg_type, src_len, dst_len, txn_tag), where src_len and dst_len are single-byte unsigned-char fields (0-255). Because the service runs under Python 2.6 (EOL since 2013), struct.pack('>B', n) silently truncates n modulo 256 instead of raising struct.error as modern Python does. An attacker can therefore craft a payload whose true length is 256 or 289 bytes so that the encoded destination-length byte wraps to 0 (or to a value matching the appliance's known serial number). When the receiver's read_message() function evaluates 'if destination_length:', a wrapped-to-zero length causes destination to be set to an empty string, which bypasses the check that normally validates the message's destination against the appliance's serial number. The now-unauthenticated message body is then passed directly to cPickle.loads(), Python's insecure object deserializer, allowing an attacker-supplied pickle object with a __reduce__ gadget to execute arbitrary OS commands with root privileges via a single crafted HTTP request — no credentials, no user interaction. Cisco's advisory (cisco-sa-sma-attack-N9bf4, published 2025-12-17, updated 2026-01-15) describes the flaw generically as 'Insufficient validation of HTTP requests by the Spam Quarantine feature'; STAR Labs' 2026-02-05 patch-diffing research against AsyncOS 15.5.4 (which adds explicit destination-length validation) reverse-engineered the true integer-overflow/pickle root cause and published a working proof-of-concept demonstrating both the serial-matching and universal zero-length bypass techniques. Cisco Talos separately confirmed exploitation in the wild dating to at least late November 2025 by a Chinese-nexus actor tracked as UAT-9686 (moderate confidence), which Talos assesses shares TTP, infrastructure, and victimology overlaps with APT41 and UNC5174. Post-exploitation, UAT-9686 deployed a persistent Python backdoor (AquaShell) embedded into the appliance's existing EUQ web server file at /data/web/euq_webui/htdocs/index.py, a compiled Go ELF reverse-SSH tunneling implant derived from the open-source ReverseSSH project (AquaTunnel), the open-source Chisel tunneling tool for pivoting into internal networks, and a log-sanitization utility (AquaPurge) that uses egrep-style keyword filtering to strip incriminating lines from appliance logs. Exploitation requires the Spam Quarantine feature to be enabled and its EUQ/administrative interface exposed to the internet — not the default configuration, which limits the vulnerable population but does not reduce severity for exposed appliances. CISA added CVE-2025-20393 to the Known Exploited Vulnerabilities catalog on 2025-12-17 with a Federal Civilian Executive Branch remediation deadline of 2025-12-24. No workaround exists; Cisco recommends taking the Spam Quarantine feature off the internet, restricting access to trusted hosts, and rebuilding/reimaging any appliance confirmed compromised, since AquaShell and AquaTunnel persistence can survive simple config resets.
MITRE ATT&CK techniques used in TL-2026-1541
Collection
Discovery
T1016 System Network Configuration Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1059.006 Python
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1571 Non-Standard Port; T1572 Protocol Tunneling
Initial Access
T1190 Exploit Public-Facing Application
Persistence
T1505.003 Web Shell; T1554 Compromise Host Software Binary
Lateral Movement
Resource Development
defense-impairment
Affected products and versions in CVE-2025-20393
- Cisco — Secure Email Gateway (formerly Email Security Appliance / ESA)
Vulnerable versions: 14.2 and earlier; 15.0; 15.5; 16.0
Fixed in: 15.0.5-016; 15.5.4-012; 16.0.4-016 - Cisco — Secure Email and Web Manager (formerly Content Security Management Appliance / SMA)
Vulnerable versions: 15.0 and earlier; 15.5; 16.0
Fixed in: 15.0.2-007; 15.5.4-007; 16.0.4-010
Remediation for CVE-2025-20393
Patches
- Cisco Secure Email Gateway: upgrade to AsyncOS 15.0.5-016, 15.5.4-012, or 16.0.4-016
- Cisco Secure Email and Web Manager: upgrade to AsyncOS 15.0.2-007, 15.5.4-007, or 16.0.4-010
Immediate actions
- Remove the Spam Quarantine / EUQ web interface (TCP port 83, quarantine UI commonly port 6025) from direct internet exposure immediately
- Restrict administrative and EUQ interfaces to trusted internal hosts and VPN-only access via firewall ACLs
- Hunt for AquaShell, AquaTunnel, AquaPurge and Chisel artifacts and outbound connections to known UAT-9686 infrastructure (172.233.67.176, 172.237.29.147, 38.54.56.95)
- Inspect /data/web/euq_webui/htdocs/index.py and other EUQ web server files for unauthorized modifications
- Rebuild or reimage any Secure Email Gateway / Secure Email and Web Manager appliance with confirmed or suspected compromise indicators — configuration resets alone do not reliably remove implanted persistence
- Review appliance and upstream firewall/proxy logs for anomalous >256-byte payloads to the EUQ RPC service and unauthenticated HTTP POST requests carrying encoded/base64 command data
Workarounds
- No vendor-supported workaround exists; the only mitigation prior to patching is removing internet exposure of the Spam Quarantine/EUQ feature
Longer-term hardening
- Apply the vendor patch (AsyncOS 15.0.5-016 / 15.5.4-012 / 16.0.4-016 for Secure Email Gateway; 15.0.2-007 / 15.5.4-007 / 16.0.4-010 for Secure Email and Web Manager) across the full appliance fleet
- Establish a policy that Spam Quarantine / EUQ interfaces are never directly internet-facing; require VPN or reverse-proxy with authentication in front of any externally reachable email-security management interface
- Deploy EDR/host monitoring on appliances where supported and integrate appliance syslog into SIEM/XDR for anomaly detection
- Enforce SAML/LDAP-based strong authentication for administrative access and disable unused services (HTTP, FTP, Telnet) on the appliance
- Subscribe to Cisco PSIRT and Talos IOC feeds (Cisco-Talos/IOCs GitHub repository) to stay current on UAT-9686 and related infrastructure
CVEs associated with CVE-2025-20393
CVE-2025-20393
Weaknesses (CWE) in CVE-2025-20393
Timeline of CVE-2025-20393
- The vulnerable AsyncOS 15.5.3 firmware build (running the legacy Python 2.6 EUQ RPC service later found to silently truncate struct.pack() length fields) is compiled, per STAR Labs' patch-diffing analysis of the firmware image.
- UAT-9686 begins exploiting CVE-2025-20393 in the wild against internet-exposed Cisco Secure Email Gateway / Secure Email and Web Manager Spam Quarantine interfaces (activity later dated by Cisco Talos to at least late November 2025).
- Cisco becomes aware of active exploitation activity targeting AsyncOS Spam Quarantine feature and begins incident investigation with Talos.
- CISA adds CVE-2025-20393 to the Known Exploited Vulnerabilities catalog, setting a Federal Civilian Executive Branch remediation deadline.
- Cisco publishes security advisory cisco-sa-sma-attack-N9bf4 disclosing CVE-2025-20393 (CVSS 10.0) as 'Insufficient validation of HTTP requests by the Spam Quarantine feature'; Cisco Talos publishes UAT-9686 campaign analysis detailing AquaShell, AquaTunnel, AquaPurge and Chisel.
- CISA-mandated remediation deadline for Federal Civilian Executive Branch agencies to mitigate CVE-2025-20393.
- Cisco updates advisory cisco-sa-sma-attack-N9bf4 to version 2.0 with confirmed fixed AsyncOS releases (15.0.5-016 / 15.5.4-012 / 16.0.4-016 for Secure Email Gateway; 15.0.2-007 / 15.5.4-007 / 16.0.4-010 for Secure Email and Web Manager).
- STAR Labs researchers obtain the vulnerable AsyncOS 15.5.3 firmware image and begin binary-diffing it against the patched 15.5.4 release to isolate the exact code change addressing CVE-2025-20393.
- STAR Labs publishes 'Pickling the Mailbox,' a patch-diffing deep dive that reverse-engineers the true single-byte struct.pack() integer-overflow / pickle-deserialization root cause and releases a working proof-of-concept covering both the serial-matching and universal zero-length authentication-bypass techniques.
Sources cited for CVE-2025-20393
- Pickling the Mailbox: A Deep Dive into CVE-2025-20393
- Cisco Security Advisory: Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager (cisco-sa-sma-attack-N9bf4)
- CVE-2025-20393 Detail
- CISA Known Exploited Vulnerabilities Catalog Entry
- UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
- CVE-2025-20393 Exploitation: A Maximum-Severity Zero-Day Vulnerability in Cisco AsyncOS Software Abused in Attacks by the China-Backed APT UAT-9686
- Cisco Zero-Day Vulnerability (CVE-2025-20393) Exploited in the Wild
- CVE-2025-20393: Threat Campaign Targeting Cisco Secure Email Gateway
- China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear
- Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances
Detection coverage for TL-2026-1541
As of 2026-02-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1541 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.