Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances, allowing attackers to execute arbitrary commands with ro...
Cisco has released fixes for CVE-2025-20393, a zero-day vulnerability in AsyncOS. This vulnerability has been exploited by suspected Chinese threat actors since November 2025, affecting users of Cisco's AsyncOS software.
Cisco identified a critical zero-day vulnerability, tracked as CVE-2025-20393, in its Secure Email products, which was actively exploited by the China-linked APT group UAT-9686. The flaw, affecting Secure Email Gateway and Email and Web Manager, was assigned a CVSS score of 10.0, indicating maximum...
Cisco has disclosed a critical zero-day remote code execution vulnerability, CVE-2026-20045, affecting multiple Unified Communications products. This flaw allows unauthenticated attackers to execute arbitrary commands on the underlying operating system, potentially gaining root access. The Cisco Pro...