Threat reportVulnerabilityTL-2026-1541

CVE-2025-20393 — Cisco Secure Email Gateway RPC Integer Overflow Enabling Auth Bypass and Unsafe Pickle Deserialization (CVSS 10.0), Exploited by China-Nexus APT UAT-9686

criticalACTIVE

CVE-2025-20393 (TL-2026-1541), also tracked as Pickling the Mailbox, is a critical-severity software vulnerability scored CVSS 10, first published 2026-02-05. It is attributed to UAT-9686 (China) with medium confidence, affects Cisco Secure Email Gateway (formerly Email Security Appliance / ESA), references 1 CVE (CVE-2025-20393), maps to 18 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 17 indicators of compromise.

CVSS
10/10Critical
CVEs
1Referenced vulnerabilities
Techniques
18MITRE ATT&CK
Actors
1UAT-9686
Detection rules
9SPL · KQL · Sigma
IOCs
17Indicators of compromise

Key facts for TL-2026-1541

Threat ID
TL-2026-1541
Also known as
Pickling the Mailbox, AsyncOS EUQ RPC Integer Overflow
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
UAT-9686
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, technology, critical-infrastructure, telecoms
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
17

Malware and tooling in CVE-2025-20393

Malware and tooling: AquaPurge, AquaShell, AquaTunnel, Chisel, ReverseSSH

How CVE-2025-20393 works

A single-byte integer overflow in the EUQ RPC message header of Cisco AsyncOS Software (Secure Email Gateway / Secure Email and Web Manager) lets an unauthenticated remote attacker bypass serial-number authentication and trigger unsafe cPickle deserialization for arbitrary command execution as root. Cisco confirmed active exploitation since late November 2025 by China-nexus actor UAT-9686, which deployed the AquaShell Python backdoor, AquaTunnel (ReverseSSH-derived) and Chisel tunnels, and the AquaPurge log-cleaning utility.

CVE-2025-20393 affects the Spam Quarantine / End User Quarantine (EUQ) RPC service (TCP port 83, quarantine web UI commonly on port 6025) shipped in Cisco AsyncOS Software for Secure Email Gateway (formerly Email Security Appliance) and Secure Email and Web Manager (formerly Content Security Management Appliance). The EUQ RPC wire format uses the struct layout '>BBIIBB32s' (version, ttl, msg_len, msg_type, src_len, dst_len, txn_tag), where src_len and dst_len are single-byte unsigned-char fields (0-255). Because the service runs under Python 2.6 (EOL since 2013), struct.pack('>B', n) silently truncates n modulo 256 instead of raising struct.error as modern Python does. An attacker can therefore craft a payload whose true length is 256 or 289 bytes so that the encoded destination-length byte wraps to 0 (or to a value matching the appliance's known serial number). When the receiver's read_message() function evaluates 'if destination_length:', a wrapped-to-zero length causes destination to be set to an empty string, which bypasses the check that normally validates the message's destination against the appliance's serial number. The now-unauthenticated message body is then passed directly to cPickle.loads(), Python's insecure object deserializer, allowing an attacker-supplied pickle object with a __reduce__ gadget to execute arbitrary OS commands with root privileges via a single crafted HTTP request — no credentials, no user interaction. Cisco's advisory (cisco-sa-sma-attack-N9bf4, published 2025-12-17, updated 2026-01-15) describes the flaw generically as 'Insufficient validation of HTTP requests by the Spam Quarantine feature'; STAR Labs' 2026-02-05 patch-diffing research against AsyncOS 15.5.4 (which adds explicit destination-length validation) reverse-engineered the true integer-overflow/pickle root cause and published a working proof-of-concept demonstrating both the serial-matching and universal zero-length bypass techniques. Cisco Talos separately confirmed exploitation in the wild dating to at least late November 2025 by a Chinese-nexus actor tracked as UAT-9686 (moderate confidence), which Talos assesses shares TTP, infrastructure, and victimology overlaps with APT41 and UNC5174. Post-exploitation, UAT-9686 deployed a persistent Python backdoor (AquaShell) embedded into the appliance's existing EUQ web server file at /data/web/euq_webui/htdocs/index.py, a compiled Go ELF reverse-SSH tunneling implant derived from the open-source ReverseSSH project (AquaTunnel), the open-source Chisel tunneling tool for pivoting into internal networks, and a log-sanitization utility (AquaPurge) that uses egrep-style keyword filtering to strip incriminating lines from appliance logs. Exploitation requires the Spam Quarantine feature to be enabled and its EUQ/administrative interface exposed to the internet — not the default configuration, which limits the vulnerable population but does not reduce severity for exposed appliances. CISA added CVE-2025-20393 to the Known Exploited Vulnerabilities catalog on 2025-12-17 with a Federal Civilian Executive Branch remediation deadline of 2025-12-24. No workaround exists; Cisco recommends taking the Spam Quarantine feature off the internet, restricting access to trusted hosts, and rebuilding/reimaging any appliance confirmed compromised, since AquaShell and AquaTunnel persistence can survive simple config resets.

MITRE ATT&CK techniques used in TL-2026-1541

Collection

T1005 Data from Local System

Discovery

T1016 System Network Configuration Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information

Execution

T1059 Command and Scripting Interpreter; T1059.004 Unix Shell; T1059.006 Python

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1571 Non-Standard Port; T1572 Protocol Tunneling

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505.003 Web Shell; T1554 Compromise Host Software Binary

Lateral Movement

T1570 Lateral Tool Transfer

Resource Development

T1587.004 Exploits

defense-impairment

T1685.006 Clear Linux or Mac System Logs

Affected products and versions in CVE-2025-20393

  • Cisco — Secure Email Gateway (formerly Email Security Appliance / ESA)
    Vulnerable versions: 14.2 and earlier; 15.0; 15.5; 16.0
    Fixed in: 15.0.5-016; 15.5.4-012; 16.0.4-016
  • Cisco — Secure Email and Web Manager (formerly Content Security Management Appliance / SMA)
    Vulnerable versions: 15.0 and earlier; 15.5; 16.0
    Fixed in: 15.0.2-007; 15.5.4-007; 16.0.4-010

Remediation for CVE-2025-20393

Patches

  • Cisco Secure Email Gateway: upgrade to AsyncOS 15.0.5-016, 15.5.4-012, or 16.0.4-016
  • Cisco Secure Email and Web Manager: upgrade to AsyncOS 15.0.2-007, 15.5.4-007, or 16.0.4-010

Immediate actions

  • Remove the Spam Quarantine / EUQ web interface (TCP port 83, quarantine UI commonly port 6025) from direct internet exposure immediately
  • Restrict administrative and EUQ interfaces to trusted internal hosts and VPN-only access via firewall ACLs
  • Hunt for AquaShell, AquaTunnel, AquaPurge and Chisel artifacts and outbound connections to known UAT-9686 infrastructure (172.233.67.176, 172.237.29.147, 38.54.56.95)
  • Inspect /data/web/euq_webui/htdocs/index.py and other EUQ web server files for unauthorized modifications
  • Rebuild or reimage any Secure Email Gateway / Secure Email and Web Manager appliance with confirmed or suspected compromise indicators — configuration resets alone do not reliably remove implanted persistence
  • Review appliance and upstream firewall/proxy logs for anomalous >256-byte payloads to the EUQ RPC service and unauthenticated HTTP POST requests carrying encoded/base64 command data

Workarounds

  • No vendor-supported workaround exists; the only mitigation prior to patching is removing internet exposure of the Spam Quarantine/EUQ feature

Longer-term hardening

  • Apply the vendor patch (AsyncOS 15.0.5-016 / 15.5.4-012 / 16.0.4-016 for Secure Email Gateway; 15.0.2-007 / 15.5.4-007 / 16.0.4-010 for Secure Email and Web Manager) across the full appliance fleet
  • Establish a policy that Spam Quarantine / EUQ interfaces are never directly internet-facing; require VPN or reverse-proxy with authentication in front of any externally reachable email-security management interface
  • Deploy EDR/host monitoring on appliances where supported and integrate appliance syslog into SIEM/XDR for anomaly detection
  • Enforce SAML/LDAP-based strong authentication for administrative access and disable unused services (HTTP, FTP, Telnet) on the appliance
  • Subscribe to Cisco PSIRT and Talos IOC feeds (Cisco-Talos/IOCs GitHub repository) to stay current on UAT-9686 and related infrastructure

CVEs associated with CVE-2025-20393

CVE-2025-20393

Weaknesses (CWE) in CVE-2025-20393

CWE-20, CWE-190, CWE-502, CWE-287

Timeline of CVE-2025-20393

  • The vulnerable AsyncOS 15.5.3 firmware build (running the legacy Python 2.6 EUQ RPC service later found to silently truncate struct.pack() length fields) is compiled, per STAR Labs' patch-diffing analysis of the firmware image.
  • UAT-9686 begins exploiting CVE-2025-20393 in the wild against internet-exposed Cisco Secure Email Gateway / Secure Email and Web Manager Spam Quarantine interfaces (activity later dated by Cisco Talos to at least late November 2025).
  • Cisco becomes aware of active exploitation activity targeting AsyncOS Spam Quarantine feature and begins incident investigation with Talos.
  • CISA adds CVE-2025-20393 to the Known Exploited Vulnerabilities catalog, setting a Federal Civilian Executive Branch remediation deadline.
  • Cisco publishes security advisory cisco-sa-sma-attack-N9bf4 disclosing CVE-2025-20393 (CVSS 10.0) as 'Insufficient validation of HTTP requests by the Spam Quarantine feature'; Cisco Talos publishes UAT-9686 campaign analysis detailing AquaShell, AquaTunnel, AquaPurge and Chisel.
  • CISA-mandated remediation deadline for Federal Civilian Executive Branch agencies to mitigate CVE-2025-20393.
  • Cisco updates advisory cisco-sa-sma-attack-N9bf4 to version 2.0 with confirmed fixed AsyncOS releases (15.0.5-016 / 15.5.4-012 / 16.0.4-016 for Secure Email Gateway; 15.0.2-007 / 15.5.4-007 / 16.0.4-010 for Secure Email and Web Manager).
  • STAR Labs researchers obtain the vulnerable AsyncOS 15.5.3 firmware image and begin binary-diffing it against the patched 15.5.4 release to isolate the exact code change addressing CVE-2025-20393.
  • STAR Labs publishes 'Pickling the Mailbox,' a patch-diffing deep dive that reverse-engineers the true single-byte struct.pack() integer-overflow / pickle-deserialization root cause and releases a working proof-of-concept covering both the serial-matching and universal zero-length authentication-bypass techniques.

Sources cited for CVE-2025-20393

Detection coverage for TL-2026-1541

As of 2026-02-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1541 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
17 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats