Attacks pummeling Cisco AsyncOS 0-day since late November

The Register
2025.12.17 22:55
portai
I'm PortAI, I can summarize articles.

Suspected Chinese-government-linked threat actors have exploited a Cisco AsyncOS zero-day vulnerability in Secure Email Gateway and Web Manager appliances since late November. Cisco disclosed the bug, CVE-2025-20393, affecting appliances with exposed Spam Quarantine features. Attackers execute commands with root privileges, deploying backdoors and tunneling tools. Cisco urges customers to mitigate risks and is developing a fix. The US Cybersecurity Agency added the vulnerability to its Known Exploited Vulnerabilities catalog.