<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Critical Cisco Zero-Day Exploited by Chinese Hackers Targeting Infrastructure

Cisco's Secure Email Gateway zero-day (CVE-2025-20393) exploited by APT41; urgent patching required by Dec 24, 2025.
Content Team

Cisco confirmed active exploitation of a critical zero-day vulnerability (CVE-2025-20393) in its Secure Email Gateway appliances, scoring a maximum 10.0 CVSS rating. Chinese threat actors UAT-9686, linked to APT41, have been exploiting the flaw since November 2025 to execute remote commands with root privileges.

The attackers deploy custom tools including AquaShell backdoor and AquaTunnel for network pivoting, primarily targeting telecommunications and critical infrastructure for espionage. CISA added the vulnerability to its Known Exploited Vulnerabilities list, requiring federal agencies to patch by December 24, 2025.

Cisco released patches and urges immediate upgrades, as no workarounds exist for this internet-exposed vulnerability.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo