Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Campaign Security Patch Release

Cisco AsyncOS email appliance zero-day exploitation and remediation

Updated 16.01.2026 07:38
Case score 66
Case score 66 Members 3 Latest activity 16.01.2026 07:38 Active exploitation Patch available CVSS: 10.0 Critical
Active exploitation Patch available CVSS: 10.0 Critical
Members 3 First seen 17.12.2025 20:45 Last seen 16.01.2026 07:38 Updated 16.01.2026 07:38

Overview

**CVE-2025-20393** in **Cisco AsyncOS** is being actively used against **Cisco Secure Email Gateway** and **Cisco Secure Email and Web Manager** appliances when **Spam Quarantine** is internet-reachable. Cisco said **UAT-9686** used the flaw as a zero-day to gain root command execution and establish persistence with tunneling and log-clearing tooling. Cisco has released fixes and hardening guidance, and confirmed compromises may require rebuilding the appliance to clear persistence. **CVE-2025-20393** is also in **CISA's KEV** catalog, while the full reach of the activity remains unquantified.