Cisco email security products actively targeted in zero-day campaign

Cisco email security products actively targeted in zero-day campaign

By Sead Fadilpašić
Publication Date: 2025-12-19 19:30:00


  • Cisco confirms zero‑day (CVE‑2025‑20393) in Secure Email appliances exploited by China‑linked actors
  • Attackers deployed Aquashell backdoor, tunneling tools, and log‑clearing utilities for persistence
  • CISA added flaw to KEV; agencies must remediate/stop use by December 24

A China-affiliated threat actor has been abusing a zero-day vulnerability in multiple Cisco email appliances to gain access to the underlying system and establish persistence.

Cisco confirmed the news in a blog post and a security advisory, urging users to apply provided recommendations and harden their networks.