logo

Cisco finally fixes max-severity bug under active attack for weeks

ID: de5343e8-35ba-5431-82cd-915641c5913e

STIX ID: report--de5343e8-35ba-5431-82cd-915641c5913e

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-01-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Cisco disclosed and patched a maximum-severity AsyncOS vulnerability (CVE-2025-20393) being actively exploited to gain root on SEG and SEWM appliances; Talos attributed the campaign to China-linked UAT-9686 and Cisco’s updates also remove persistence installed by the attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.