Cisco Secure Email Gateway CVSS 10.0 Zero-Day Via the Spam Filter episode artwork

EPISODE · Jan 16, 2026 · 8 MIN

Cisco Secure Email Gateway CVSS 10.0 Zero-Day Via the Spam Filter

from IT SPARC Cast

This week on IT SPARC Cast – CVE of the Week, John Barger and Lou Schmidt break down CVE-2025-20393, a CVSS 10.0 zero-day vulnerability affecting Cisco Secure Email Gateway (SEG) and related AsyncOS-based email security products.The flaw is actively exploited in the wild, remains unpatched, and—ironically—uses the spam filtering engine itself as the attack vector. With no user interaction required and evidence of nation-state activity, this vulnerability represents a worst-case scenario for organizations relying on Cisco’s email security stack.If you run Cisco Secure Email Gateway or Email Security Appliances, this is an emergency-level issue that demands immediate attention.⸻📌 Show Notes🚨 CVE of the Week: CVE-2025-20393•Severity: CVSS 10.0 (Critical)•Status: Actively exploited, no patch available•Vendor: Cisco🎯 Affected Products•Cisco Secure Email Gateway (SEG)•Cisco Email Security Appliance (ESA)•Cisco Secure Email and Web Manager (SEWM)•All affected systems run Cisco AsyncOS🔓 How the Exploit Works•Attackers deliver a specially crafted email that is processed before a spam verdict is reached•The payload is executed during email parsing, attachment handling, or content inspection•No user interaction required•The malicious email never needs to reach an inbox💥 Real-World Impact•Full remote code execution on the email gateway•Email interception and exfiltration (espionage risk)•Persistent access for follow-on attacks•Credential harvesting and downstream phishing using trusted infrastructure•Log wiping, making detection extremely difficult🌍 Threat Activity•Exploits observed as early as November 2025•Linked to Chinese state-aligned actors•Tracked under UAT-9686, associated with groups such as APT41 and UNC5174•Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog🛡️ Mitigation Guidance (No Patch Available)•Immediately restrict and segment management interfaces•Tighten ACLs and allow lists•Treat SEG as Tier-Zero-adjacent infrastructure•If compromise is suspected: full system rebuild required•Assume persistence due to log tampering🧠 Commentary•The exploit weaponizes the very system designed to stop malicious email•Lack of a patch from a vendor of Cisco’s size raises serious concerns•For some organizations, this may prompt reevaluation of email security platforms altogether⸻🔚 Wrap-Up & Listener FeedbackWe want to thank listeners who continue to engage with the show and help shape the conversation:•GFABasic32 wrote:“Thanks for the emergency update on n8n. I love the balance of technical deep dives and high-level strategy. You guys make keeping up with CVEs actually entertaining.”•Dennis added:“I love the CVE of the Week. These episodes are like exposure therapy.”That’s exactly the goal—helping you face what’s happening in security so you can respond, not react.Have thoughts on this CVE or want us to cover another one? Reach out.⸻🔗 Social LinksIT SPARC Cast@ITSPARCCast on Xhttps://www.linkedin.com/company/sparc-sales/ on LinkedInJohn Barger@john_Video on Xhttps://www.linkedin.com/in/johnbarger/ on LinkedInLou Schmidt@loudoggeek on Xhttps://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn Hosted on Acast. See acast.com/privacy for more information.

NOW PLAYING

Cisco Secure Email Gateway CVSS 10.0 Zero-Day Via the Spam Filter

0:00 8:53

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Breaking News Show | eTurboNews Juergen Thomas Steinmetz News is relevant to the global travel and tourism industry, human rights and global issues.Breaking news when it happens and only from the source. LIGHTS, CAMERA, SMILE! Creatives Club Media Lights, Camera, Smile, is a podcast for anyone with a dream to share something with the world, out of the overflow of themselves - be it their mind, their heart, their personalities, and much more. Each of us are alive in this moment in time, with an innate ability to have ideas and create various things to benefit both ourselves and the people around us for a reason, and here, you will find the encouragement, the inspiration, and the motivation to do just that. Hosted by Cicily, founder of Creatives Club, she dives into various topics surrounding creativity and business. Exploring entrepreneurship for creatives in a corporate reality, sharing tips and tricks in a media centered company, answering questions regarding what a creative actually is are just a few of the things discussed on this podcast. Be encouraged to create for yourself as Cicily gets vulnerable by pivoting the camera to herself for the first time.To submit questions for Cicily to answer, or have her address certain t Invictus by Greyana, A Tomione Podfic M+G Readings Sporadic uploads thanks to gallstones.Voldemort intended the object to be used by his most loyal follower in the event that his horcruxes were destroyed, but it ended up in Hermione’s possession instead.It sent her back to a time when he was much less the monster that she’d always known him to be. Nothing could have prepared her for the intelligence and charm of Tom Riddle.He isn’t who she thought he was.Hermione discovers that it’s a dark descent into the madness of the man she should hate, but can’t… a descent she will never emerge fr The Course Mentors Podcast The Course Mentors Hey there, future course creator!Ever feel like turning your know-how into an online course is like trying to solve a Rubik's cube blindfolded? Well, grab your headphones because "The Course Mentors Podcast" is here to be your secret weapon!Meet Aimee and Odette (that's us!), your new best friends in the course creation world. We've been in the trenches for over a decade, and for the last five years, we've been rocking the online course space. Now we're here to spill all our secrets in bite-sized, 15-20 minute episodes that'll fit perfectly in your coffee breaks.No fluff, no filler - just real, actionable advice that'll take you from "um, what's a landing page?" to "holy moly, I just hit six figures!". We're talking everything from crafting your course to marketing it like a pro and building a business that'll have you pinching yourself.Whether you're dreaming of ditching the 9-to-5 grind, adding a sweet extra income str

Frequently Asked Questions

How long is this episode of IT SPARC Cast?

This episode is 8 minutes long.

When was this IT SPARC Cast episode published?

This episode was published on January 16, 2026.

What is this episode about?

This week on IT SPARC Cast – CVE of the Week, John Barger and Lou Schmidt break down CVE-2025-20393, a CVSS 10.0 zero-day vulnerability affecting Cisco Secure Email Gateway (SEG) and related AsyncOS-based email security products.The flaw is actively...

Can I download this IT SPARC Cast episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!