Blog.Talosintelligence
Cisco Fixes Critical AsyncOS Vulnerability Under Attack
First seen 16 Jan 2026, 03:59 UTC
•



+4
•95.8
Export
Article Content
Browse articles
Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances, allowing attackers to execute arbitrary commands with root privileges. Cisco first detected attacks targeting these appliances on December 10.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure