logo

Cisco warns of unpatched AsyncOS zero-day exploited in attacks

ID: f498c64b-5119-5867-91ed-b277bed1a05e

STIX ID: report--f498c64b-5119-5867-91ed-b277bed1a05e

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-12-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco Talos warns of a high-severity, actively exploited, unpatched AsyncOS zero-day (CVE-2025-20393) impacting Cisco Secure Email Gateway and Secure Email and Web Manager appliances with exposed Spam Quarantine; the attacker, tracked as UAT-9686 (Chinese-nexus APT), is observed deploying AquaShell persistence, reverse-tunnel implants (AquaTunnel, Chisel), and log-purging tools, with IOCs published and Cisco recommending restricting access, rebuilding compromised appliances, and following mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.