Cisco
Cisco Asyncos: vulnerabilities and CVEs
Cisco Asyncos has 57 published vulnerabilities, 4 of them in the last 12 months. 2 are rated critical and 2 are listed by CISA as actively exploited.
CVEs57
Last 12 months4
Critical2
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76461 | Critical (9.8) | 28% | ⚠ Active exploitation | Sep 14, 2026 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying… |
| CVE-2025-20393 | Critical (10) | 32% | ⚠ Active exploitation | Dec 17, 2025 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76461 | Critical (9.8) | 28% | ⚠ Active exploitation | Sep 14, 2026 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying… |
| CVE-2026-20152 | Medium (5.3) | 0.30% | — | Apr 15, 2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This… |
| CVE-2026-20056 | Medium (4) | 0.15% | — | Feb 4, 2026 | A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware… |
| CVE-2025-20393 | Critical (10) | 32% | ⚠ Active exploitation | Dec 17, 2025 | A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system… |
| CVE-2020-3122 | Medium (5.3) | 0.39% | — | Mar 4, 2025 | A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information. |
| CVE-2025-20185 | Medium (6.7) | 0.19% | — | Feb 5, 2025 | A vulnerability in the implementation of the remote access functionality of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance could allow an… |
| CVE-2025-20184 | High (7.2) | 0.86% | — | Feb 5, 2025 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Web Appliance could allow an authenticated, remote attacker to perform command injection… |
| CVE-2025-20183 | Medium (5.3) | 0.44% | — | Feb 5, 2025 | The vulnerability is due to improper handling of a crafted range request header. An attacker could exploit this vulnerability by sending an HTTP request with a crafted range request header through the affected device. A… |
| CVE-2025-20180 | Medium (4.8) | 0.32% | — | Feb 5, 2025 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an authenticated, remote attacker to conduct a stored… |
| CVE-2021-1425 | Medium (6.5) | 0.53% | — | Nov 18, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive… |
| CVE-2022-20871 | High (8.8) | 1.9% | — | Nov 15, 2024 | A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform… |
| CVE-2024-20504 | Medium (5.4) | 0.28% | — | Nov 6, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance could allow an authenticated, remote attacker to… |
| CVE-2024-20435 | High (7.8) | 0.16% | — | Jul 17, 2024 | A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability is due to insufficient… |
| CVE-2024-20429 | High (7.2) | 0.62% | — | Jul 17, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This… |
| CVE-2024-20392 | Medium (6.1) | 0.39% | — | May 15, 2024 | A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability… |
| CVE-2024-20383 | High (8.4) | 0.35% | — | May 15, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct an XSS attack against a user of the… |
| CVE-2024-20258 | Medium (6.1) | 0.32% | — | May 15, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack… |
| CVE-2024-20257 | Medium (4.8) | 0.29% | — | May 15, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r… |
| CVE-2024-20256 | Medium (4.8) | 0.29% | — | May 15, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack… |
| CVE-2020-26082 | Medium (5.3) | 0.63% | — | Aug 4, 2023 | A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are configured on an… |
| CVE-2023-20215 | Medium (5.3) | 0.62% | — | Aug 3, 2023 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a network that should… |
| CVE-2022-20952 | Medium (5.3) | 0.68% | — | Mar 1, 2023 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a… |
| CVE-2023-20057 | Medium (5.3) | 0.68% | — | Jan 20, 2023 | A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected… |
| CVE-2022-20942 | Medium (6.5) | 0.95% | — | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA),… |
| CVE-2022-20868 | High (8.8) | 0.74% | — | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate… |
| CVE-2022-20867 | Medium (6.5) | 0.80% | — | Nov 4, 2022 | A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on… |
| CVE-2022-20781 | Medium (5.4) | 0.58% | — | Apr 6, 2022 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack… |
| CVE-2022-20675 | Medium (5.3) | 1.3% | — | Apr 6, 2022 | A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an… |
| CVE-2022-20653 | High (7.5) | 1.8% | — | Feb 17, 2022 | A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to… |
| CVE-2021-34741 | High (7.5) | 1.3% | — | Nov 4, 2021 | A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.