Chinese attackers exploiting zero-day to target Cisco email security products
ID: 5be5c993-cf3f-5ac6-b7c7-3f4f4a8f46b2
STIX ID: report--5be5c993-cf3f-5ac6-b7c7-3f4f4a8f46b2
Feed Name: The Record from Recorded Future News
Cisco reported active exploitation of CVE-2025-20393 (CVSS 10) in AsyncOS for its Secure Email Gateway and Secure Email and Web Manager appliances by a Chinese-linked group (UAT-9686, with ties to APT41). The vulnerability—exposed when a spam prevention feature/ports are reachable from the internet—had no patch at the time; attackers used a persistence tool called AquaShell. CISA confirmed exploitation and ordered mitigations; Cisco advises restricting access, rebuilding compromised appliances, and following provided mitigation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
