CVE-2025-20393 is a vulnerability tracked across 16 threat clusters and 29 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity March 4, 2026.
Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…
Cisco has released fixes for CVE-2025-20393, a zero-day vulnerability in AsyncOS. This vulnerability has been exploited by suspected Chinese threat actors since November 2025, affecting users of Cisco's AsyncOS software.
Cisco identified a critical zero-day vulnerability, tracked as CVE-2025-20393, in its Secure Email products, which was actively exploited by the China-linked APT group UAT-9686. The flaw, affecting Secure Email Gateway…
Cisco has disclosed a critical zero-day remote code execution vulnerability, CVE-2026-20045, affecting multiple Unified Communications products. This flaw allows unauthenticated attackers to execute arbitrary commands…
A critical remote code execution vulnerability (CVE-2025-68613) in the n8n workflow automation platform has been disclosed, potentially impacting over 100,000 servers, primarily in the United States. The flaw, which has…
China-linked hackers are exploiting a critical zero-day vulnerability tracked as CVE-2025-20393. This vulnerability affects Secure Email Gateway and Secure Email and Web Manager appliances, posing risks to organizations…
Cisco has confirmed a zero-day vulnerability (CVE-2025-20393) in its Secure Email appliances that is being exploited by actors linked to China. The attackers have deployed the Aquashell backdoor to establish persistence…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
In mid-2025, the Chinese APT group Mustang Panda launched cyber-espionage attacks using a signed kernel-mode rootkit to deploy the ToneShell backdoor. The attacks targeted government organizations in Southeast and East…
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…