AsyncOS — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
December 18, 2025
Last Seen
January 16, 2026

Related Threat Clusters

  • Cisco Fixes Critical AsyncOS Vulnerability Under Attack

    Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…

    11 articles · Updated January 15, 2026
  • Cisco Addresses AsyncOS Zero-Day Exploited by Threat Actors

    Cisco has released fixes for CVE-2025-20393, a zero-day vulnerability in AsyncOS. This vulnerability has been exploited by suspected Chinese threat actors since November 2025, affecting users of Cisco's AsyncOS software.

    3 articles · Updated January 16, 2026
  • China-linked APT UAT Exploits Cisco AsyncOS Flaw CVE-2025-20393

    Cisco identified a critical zero-day vulnerability, tracked as CVE-2025-20393, in its Secure Email products, which was actively exploited by the China-linked APT group UAT-9686. The flaw, affecting Secure Email Gateway…

    3 articles · Updated January 16, 2026
  • Chinese Hackers Exploit Cisco's AsyncOS Zero-Day Vulnerability

    Cisco has reported that Chinese hackers are exploiting a zero-day vulnerability in its AsyncOS software, which allows unauthorized root access to Secure Email appliances. The flaw affects Cisco's Secure Email Gateway…

    5 articles · Updated December 18, 2025
  • Cisco ASA Zero-Day Exploited in State-Espionage Campaign

    Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…

    27 articles · Updated December 18, 2025
  • Zero-Day Vulnerability in AsyncOS Affects Secure Email Gateway and Web Security Appliances

    A zero-day vulnerability has been identified in the AsyncOS operating system, impacting Secure Email Gateway and Web Security Appliances. These systems serve as central filters for email and web traffic, potentially…

    1 article · Updated December 20, 2025

Recent Intelligence Reports

  • Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393) — Helpnetsecurity · January 16, 2026
  • China-linked APT UAT — Securityaffairs.Co · January 16, 2026
  • Cisco's Zero-Day Nightmare: China-Linked Hackers Breach Email Defenses — Webpronews · January 16, 2026
  • Patch now! Critical Cisco vulnerability exploited since December 2025 — Heise.De · January 16, 2026
  • Cisco finally fixes max-severity bug under attack for weeks — Theregister · January 15, 2026
  • Cisco finally fixes max — Theregister · January 15, 2026
  • LeakWatch 2025 - Security incidents, IT scandals and alerts for calendar week 51 — Igorslab.De · December 20, 2025
  • Cisco says China — Cybersecuritydive · December 18, 2025

CVSS v3.1 Breakdown