Cisco customers hit by fresh wave of zero-day attacks from China
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20393 | Improper Input Validation in Cisco Secure Email and Web Appliances Allows Root Commands CVE-2025-20393 is an improper input validation flaw (CWE-20) in Cisco Secure Email Gateway, Secure Email, AsyncOS software, and Web Manager appliances that lets attackers execute arbitrary commands with root privileges on the underlying operating system. The flaw is triggered when an affected appliance processes improperly validated input, though the CISA record does not specify the access vector or whether authentication is required. Successful exploitation yields full compromise of the appliance at the highest OS privilege level, which is significant because these devices sit in the email- and web-security path of enterprise networks. Organizations running these Cisco appliances are affected; CVSS has not yet been published and no public proof-of-concept is known. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2025-12-17, EPSS estimates a 29.9% chance of exploitation within 30 days (98th percentile), and ransomware use remains undetermined. Do: Apply the mitigations or updates Cisco specifies in its advisory for CVE-2025-20393 without waiting for a CVSS score; the CISA KEV entry directs users to vendor mitigations, applicable BOD 22-01 cloud-service guidance, or discontinuing use if mitigations are unavailable. Because this record contains no fixed-release details, check the Cisco PSIRT advisory for the exact patched AsyncOS and Web Manager versions before planning the upgrade. In the meantime, review appliance logs and configurations for signs of unexpected command execution or changes, since active exploitation is confirmed and ransomware use is still unknown. | 10.0 | 30% | KEV |
| largeroughly tens of thousands of appliance deployments worldwide (exact installed base unpublished) |
Full article748 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Cisco has yet to release a patch for the actively exploited vulnerability, and attacks have been underway since at least late November.
Listen to this article
0:00
Learn more.
Cisco customers are confronting a fresh wave of attacks from a Chinese threat group that has actively exploited a critical zero-day vulnerability affecting the vendor’s software for email and web security since at least late November, the company said in an advisory Wednesday.
Cisco said it became aware of the attacks Dec. 10. The defect CVE-2025-20393, which has a CVSS rating of 10, is an improper input validation vulnerability affecting Cisco AsyncOS software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager that allows attackers to execute commands with unrestricted privileges and implant persistent backdoors on compromised devices.
There is no patch for the vulnerability and Cisco declined to say when one would be made available. Cisco said “non-standard configurations” have been observed in compromised networks, specifically customer systems that are configured with a publicly exposed spam quarantine feature.
Cisco Talos researchers attributed the attacks to a Chinese advanced persistent threat group it tracks as UAT-9686, which has used tooling and infrastructure consistent with other China state-sponsored threat groups such as APT41 and UNC5174.
Cisco declined to answer questions about how many customers have been impacted. The company encouraged customers to follow guidance in its advisory to determine if they’re exposed and take steps to mitigate risk, including isolating or rebuilding affecting systems.
The spam quarantine feature, which must be on and publicly exposed for attackers to exploit the vulnerability, is not enabled by default, Cisco said. The Cybersecurity and Infrastructure Security Agency added the zero-day to its known exploited vulnerabilities catalog Thursday.
“Highlighting non-standard configurations isn’t the same as blaming users — it’s a relevant technical detail that helps defenders assess exploitation likelihood,” Douglas McKee, director of vulnerability intelligence at Rapid7, told CyberScoop.
“The core issue doesn’t change,” he added. “The software fails under certain conditions, and that’s on the vendor to fix. Secure design means accounting for edge cases, even when it’s hard, and not shifting responsibility when they’re exploited.”
Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, said the non-standard configurations that trigger the defect is an indication attacks are targeting specific users. Yet, he added, it’s unknown how many Cisco customers have enabled the spam quarantine feature and exposed it to the internet.
Chinese threat groups have consistently exploited Cisco vulnerabilities. The latest attacks follow a widespread attack spree involving actively exploited zero-day vulnerabilities affecting Cisco firewalls.
Federal cyber authorities issued an emergency directive in September about the attacks, which impacted multiple government agencies in May. CISA and Cisco did not at that time fully explain why they waited four months from initial response to the attacks to disclose the malicious activity, patch the zero-days and issue the emergency directive.
A spokesperson for Cisco said there’s no evidence the recent attacks are connected to the attacks earlier this year. Cisco attributed the previous attacks to the same threat group behind an early 2024 campaign targeting Cisco devices, which it dubbed “ArcaneDoor.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisco-zero-day-attacks-china-apt/