logo

China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bug

ID: 544f769d-bc18-5570-ba35-2ed8fe7c9929

STIX ID: report--544f769d-bc18-5570-ba35-2ed8fe7c9929

Feed Name: Security Affairs

Threat Score
95/100

Date Published: 2026-01-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Cisco fixed a CVE-2025-20393 maximum-severity AsyncOS zero-day that was actively exploited by China-linked APT UAT-9686 to achieve root execution on exposed Secure Email Gateway and Secure Email and Web Manager appliances; attackers deployed a Python backdoor (AquaShell), reverse-tunneling tools (AquaTunnel, chisel), and a log-wiping utility (AquaPurge) to maintain stealth and persistence, and Cisco/Talos have published impacted releases and remediation guidance.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.