logo

Cisco finally fixes AsyncOS zero-day exploited since November

ID: 40767d1c-45df-50fe-8547-a9aed0f0e8f6

STIX ID: report--40767d1c-45df-50fe-8547-a9aed0f0e8f6

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-01-16

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco patched a maximum-severity AsyncOS zero-day (CVE-2025-20393) that was exploited in the wild against Secure Email Gateway and Secure Email and Web Manager appliances with internet-exposed Spam Quarantine, enabling arbitrary command execution as root. Cisco Talos links the intrusion activity since November 2025 to a Chinese-nexus APT tracked as UAT-9686, which deployed AquaShell persistence, AquaTunnel/Chisel reverse-SSH implants, and AquaPurge log-wiping; CISA added the vulnerability to its known exploited vulnerabilities catalog and ordered federal mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.