China-linked APT UAT Exploits Cisco AsyncOS Flaw CVE-2025-20393
First seen 16 Jan 2026, 13:51 UTC
•
•92
Export
Article Content
Browse articles
Cisco identified a critical zero-day vulnerability, tracked as CVE-2025-20393, in its Secure Email products, which was actively exploited by the China-linked APT group UAT-9686. The flaw, affecting Secure Email Gateway and Email and Web Manager, was assigned a CVSS score of 10.0, indicating maximum severity. Cisco has since released a patch to address the vulnerability.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Cisco Fixes Critical AsyncOS Vulnerability Under Attack
Cisco AsyncOS Zero-Day Exploited by Chinese APT Group
Cisco Secure Email Gateway Targeted by Advanced Persistent Threat
Cisco ASA Zero-Day Exploited in State-Espionage Campaign
Cisco Patches ISE Vulnerability with Public Exploit Code
Cisco Confirms Exploitation of AsyncOS Zero-Day by Chinese Hackers