Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…
A zero-day vulnerability in Cisco AsyncOS Software has been actively exploited since late November 2025. The attack targets Secure Email Gateway and Secure Email and Web Manager, allowing attackers to execute…
Cisco has disclosed a critical zero-day remote code execution vulnerability, CVE-2026-20045, affecting multiple Unified Communications products. This flaw allows unauthenticated attackers to execute arbitrary commands…
Cisco has reported that Chinese hackers are exploiting a zero-day vulnerability in its AsyncOS software, which allows unauthorized root access to Secure Email appliances. The flaw affects Cisco's Secure Email Gateway…
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
Cisco has reported an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS software, affecting Secure Email Gateway and Secure Email and Web Manager appliances. The vulnerability is being actively exploited…
GreyNoise is monitoring a coordinated credential-based attack campaign aimed at enterprise VPN authentication systems, specifically targeting Cisco SSL VPN and Palo Alto Networks GlobalProtect services. The campaign…
Chinese hackers have targeted Cisco's Secure Email Gateway and Secure Email and Web Manager appliances by exploiting an unpatched zero-day vulnerability. The threat group UAT-9686 has utilized custom-built hacking tools…