Bleepingcomputer
Cisco Confirms Exploitation of AsyncOS Zero-Day by Chinese Hackers
First seen 17 Dec 2025, 19:55 UTC
•


•77% similarity
•37.5
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Cisco has reported an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS software, affecting Secure Email Gateway and Secure Email and Web Manager appliances. The vulnerability is being actively exploited by a Chinese advanced persistent threat actor, identified as UAT-9686, targeting devices with non-standard configurations and the Spam Quarantine feature enabled.
ThreatCluster AI