Cisco Patches Critical RCE Flaw Exploited by Hackers

Cisco Patches Critical RCE Flaw Exploited by Hackers

First seen 18 Jan 2026, 21:04 UTC TechradarMsn 32.7

Article Content

Browse articles
ThreatCluster

Cisco has released a patch for a critical remote code execution vulnerability (CVE-2025-20393) affecting its Secure Email appliances. This flaw was actively exploited by Chinese state-sponsored groups for several weeks using a tool named Aquashell. The patch also addresses persistence mechanisms that may have been installed during the exploitation.