#AsyncOS
​Cisco finally patched a maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway (SEG) appliances since November 2025.
Cisco finally fixes AsyncOS zero-day exploited since November
​Cisco finally patched a maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway (SEG) appliances since November 2025.
www.bleepingcomputer.com
January 16, 2026 at 9:21 AM
​Cisco warned of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances.
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
​Cisco warned of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances.
www.bleepingcomputer.com
December 17, 2025 at 6:45 PM
Cisco finally fixes max-severity bug under active attack for weeks
Cisco finally fixes max-severity bug under active attack for weeks
This is a threat to security - and to the weekend for some unlucky netadmins Cisco finally delivered a fix for a maximum-severity bug in AsyncOS that has been under attack for at least a month.…
dlvr.it
January 15, 2026 at 11:35 PM
Wowzers, another perfect 10 from Cisco on Secure Email Gateway, Secure Mail, and Web Manager. This one has:

- RCE
- No patch
- No workaround
- No public IoCs

Recommendation is to reimage to a known-good config. Whatever that is, without indicators.

Good luck I guess??
Cisco Security Advisory: Reports About Cyberattacks Against Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
On December 10, Cisco became aware of a new cyberattack campaign targeting a limited subset of appliances with certain ports open to the internet that are running Cisco AsyncOS Software for Cisco Secu...
sec.cloudapps.cisco.com
December 17, 2025 at 4:38 PM
Cisco reports an unpatched AsyncOS zero-day: CVE-2025-20393! Specifically affects both physical & virtual appliances Cisco Secure Email Gateway, Cisco Secure Email, & Web Manager. Impacted devices have “Spam Quarantine” enabled & are exposed to the internet.
www.bleepingcomputer.com/news/securit...
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
​Cisco warned customers today of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) applia...
www.bleepingcomputer.com
December 17, 2025 at 8:40 PM
🚨Zero-day Alert‼️

Cisco Alerts on Critical 10.0 CVSS AsyncOS Zero Day Actively Exploited by China Linked APT, No Patch Available
December 19, 2025 at 8:47 AM
Cisco Warns of Active Attacks Exploiting Unpatched 0-Day in AsyncOS Email Security Appliances #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
December 18, 2025 at 9:13 PM
A suspected Chinese APT is exploiting a new Cisco zero-day

-impacts Cisco Secure Email Gateway And Cisco Secure Email and Web Manager
-CVE-2025-20393
-CVSS score: 10
-APT is UAT-9686

blog.talosintelligence.com/uat-9686/
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
Cisco Talos is tracking the active targeting of Cisco AsyncOS Software for Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and Cisco Secure Email and Web Manager, f...
blog.talosintelligence.com
December 17, 2025 at 10:36 PM
Cisco finally fixes AsyncOS zero-day exploited since November
Cisco finally fixes AsyncOS zero-day exploited since November
​Cisco finally patched a maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway (SEG) appliances since November 2025.
www.bleepingcomputer.com
January 16, 2026 at 9:32 AM
Cisco finally fixes AsyncOS zero-day exploited since November
www.bleepingcomputer.com/news/securit...
Cisco finally fixes AsyncOS zero-day exploited since November
​Cisco finally patched a maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway (SEG) appliances since November 2025.
www.bleepingcomputer.com
January 17, 2026 at 1:36 PM
🌊 ABYSSAL · critical with a public exploit
CVE-2026-76461: A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote…
CVSS 9.8 · exploited
https://beta.vulnsea.com/cve/CVE-2026-76461

#CVE #infosec #cybersecurity #threatintel
CVE-2026-76461 — A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …
beta.vulnsea.com
September 14, 2026 at 9:11 PM
❗️ Cisco warnt vor der Ausnutzung einer Zero-Day-Schwachstelle in seiner Secure E-Mail Gateway-Lösung.

Angreifer nutzen diese, um SQL-Befehle auf verwundbaren Systemen auszuführen und mit Root-Rechten zu operieren. Betreiber sollten unverzüglich aktiv werden. ➡️ https://www.bsi.bund.de/dok/1208172
Version 1.0: Cisco Secure Email Gateway - Aktive Ausnutzung einer Zero-Day-Schwachstelle
Am Abend des 14. September 2026 veröffentlichte der Netzwerkausrüster Cisco ein Advisory über eine Schwachstelle in seinem Produkt Secure Email Gateway. Demnach liegt mit CVE-2026-76461 eine Verwundbarkeit im E-Mail Parsing von AsyncOS for Cisco Secure Email Gateway vor, die es Angreifern aufgrun...
www.bsi.bund.de
September 15, 2026 at 2:30 PM
In fairness actual details are provided by Cisco just in an unlinked Talos blog separate from the security advisory...
blog.talosintelligence.com/uat-9686/
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
Cisco Talos is tracking the active targeting of Cisco AsyncOS Software for Cisco Secure Email Gateway, formerly known as Cisco Email Security Appliance (ESA), and Cisco Secure Email and Web Manager, f...
blog.talosintelligence.com
December 17, 2025 at 6:10 PM
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393) - Help Net Security www.helpnetsecurity.com/2026/01/16/c...
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393) - Help Net Security
Cisco has released fixes for CVE-2025-20393, an AsyncOS zero-day exploited by suspected Chinese threat actors since November 2025.
www.helpnetsecurity.com
January 18, 2026 at 9:06 AM
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)

Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exp…
#hackernews #news
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)
Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exploited as a zero-day by suspected Chinese attackers since at least late November 2025. The company revealed the flaw’s existence and in-the-wild exploitation on December 17, 2025, and urged customers to check whether their appliances had been breached and to rebuild them in case of …
www.helpnetsecurity.com
January 17, 2026 at 4:24 PM
No timeline for a patch Suspected Chinese-government-linked threat actors have been battering a maximum-severity Cisco AsyncOS zero-day vulnerability in some Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances for nearly a month, and there's no timeline for a fix.…
Attacks pummeling Cisco AsyncOS 0-day since late November
No timeline for a patch Suspected Chinese-government-linked threat actors have been battering a maximum-severity Cisco AsyncOS zero-day vulnerability in some Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances for nearly a month, and there's no timeline for a fix.…
go.theregister.com
December 17, 2025 at 11:30 PM
Alert: Critical zero-day in Cisco AsyncOS exploited to deploy system-level backdoors. Organizations must patch immediately to prevent compromise. #CyberSecurity #Cisco #ZeroDay #APT Link: thedailytechfeed.com/zero-day-in-...
December 18, 2025 at 5:18 PM