Cisco email security products are actively targeted in the zero-day campaign


  • Cisco Confirms Zero-Day (CVE-2025-20393) in Secure Email Appliances Exploited by China-Affiliated Actors
  • Attackers implemented Aquashell backdoor, tunneling tools, and log-clearing tools for persistence
  • CISA added errors to KEV; agencies must remedy/cease use by December 24

A China-affiliated threat actor has exploited a zero-day vulnerability in multiple Cisco email appliances to gain access to the underlying system and establish persistence.

Cisco confirmed the news in a blog post and security advisory urging users to apply the recommendations provided and harden their networks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top