Cisco Email Security Products Actively Targeted in Zero Day Campaign


  • Cisco Confirms Detection of Zero Day (CVE‑2025‑20393) in Secure Email Appliances Operated by China-Linked Actors
  • The attackers deployed an Aquashell backdoor, tunneling tools, and log clearing utilities to ensure persistence.
  • CISA added a vulnerability to KEV; agencies must remedy/stop use by December 24

A China-affiliated threat actor abused a zero-day vulnerability in multiple Cisco email devices to gain access to the underlying system and establish persistence.

Cisco confirmed the news in a blog post and security advisory, urging users to implement the recommendations provided and harden their networks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top