Cisco AsyncOS Software is a technology platform tracked across 3 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity December 18, 2025.
Cisco AsyncOS Software is Cisco's security operating system used by security appliances (notably Email Security Appliances and Web Security Appliances). A zero-day vulnerability in AsyncOS has been disclosed and is being actively exploited in the wild, enabling attackers to potentially run system-level code on affected devices, which heightens the risk to organizations relying on Cisco security appliances for protection.
A zero-day vulnerability in Cisco AsyncOS Software has been actively exploited since late November 2025. The attack targets Secure Email Gateway and Secure Email and Web Manager, allowing attackers to execute…
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
Cisco has reported an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS software, affecting Secure Email Gateway and Secure Email and Web Manager appliances. The vulnerability is being actively exploited…