#cve-2025-20393

[ follow ]
#cisco-asyncos
fromThe Hacker News
13 hours ago
Information security

Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances

A critical AsyncOS zero-day (CVE-2025-20393) enables remote root command execution when Spam Quarantine is internet-exposed, actively exploited by China-linked APT UAT-9686.
fromTheregister
19 hours ago
Information security

Attacks pummeling Cisco AsyncOS 0-day since late November

Chinese-government-linked threat actors exploit a critical Cisco AsyncOS zero-day (CVE-2025-20393) in SEG/SEWM appliances with exposed Spam Quarantine, enabling root-level arbitrary command execution.
[ Load more ]