Cisco Secure Email Gateway — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
13
occurrences
First Seen
December 17, 2025
Last Seen
January 16, 2026

Cisco Secure Email Gateway (SEG) is Cisco's email security platform that sits at the network edge to inspect and filter inbound and outbound messages, protecting against phishing, malware, and data loss.

Overview

Cisco Secure Email Gateway (SEG) is Cisco's email security platform that sits at the network edge to inspect and filter inbound and outbound messages, protecting against phishing, malware, and data loss. It runs on Cisco's AsyncOS and is widely deployed in enterprises, making its security posture and rapid patching critical as multiple zero-day vulnerabilities have been exploited in the wild, including by Chinese threat actors.

Related Threat Clusters

  • Cisco Fixes Critical AsyncOS Vulnerability Under Attack

    Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…

    11 articles · Updated January 15, 2026
  • Cisco Email Security Products Targeted in Zero-Day Campaign by China-Linked Actors

    Cisco has confirmed a zero-day vulnerability (CVE-2025-20393) in its Secure Email appliances that is being exploited by actors linked to China. The attackers have deployed the Aquashell backdoor to establish persistence…

    6 articles · Updated December 20, 2025
  • Cisco ASA Zero-Day Exploited in State-Espionage Campaign

    Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…

    27 articles · Updated December 18, 2025
  • Cisco Confirms Exploitation of AsyncOS Zero-Day by Chinese Hackers

    Cisco has reported an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS software, affecting Secure Email Gateway and Secure Email and Web Manager appliances. The vulnerability is being actively exploited…

    5 articles · Updated December 17, 2025
  • Chinese Hackers Exploit Cisco Email Security Vulnerability

    Chinese hackers have targeted Cisco's Secure Email Gateway and Secure Email and Web Manager appliances by exploiting an unpatched zero-day vulnerability. The threat group UAT-9686 has utilized custom-built hacking tools…

    2 articles · Updated December 18, 2025

Recent Intelligence Reports

  • Patch now! Critical Cisco vulnerability exploited since December 2025 — Heise.De · January 16, 2026
  • Cisco Secure Email Gateway Vulnerability Exploited: Act Now — Redhotcyber · December 21, 2025
  • 100+ Cisco Secure Email Devices Exposed to Zero‑Day Exploited in the Wild — Cybersecuritynews · December 21, 2025
  • Cisco Confirms a Zero-Day Security Flaw. Here's How Users Can Stay Protected — Techloy · December 18, 2025
  • CC-4732 — Digital.Nhs.Uk · December 18, 2025
  • Cisco confirms zero — Csoonline · December 18, 2025
  • Chinese hackers exploit Cisco email gateway zero — Cyberinsider · December 18, 2025
  • Cisco Warns of Active Cyberattack Exploiting Critical AsyncOS Vulnerability — Thecyberexpress · December 18, 2025

CVSS v3.1 Breakdown