<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cisco-zero-day-vulnerability-in-asyncos-exploited-by-chinese-hackers-o1bxv6f8l" -->

---
title: Cisco Zero-Day Vulnerability in AsyncOS Exploited by...
description: A critical zero-day vulnerability (CVE-2025-20393) in Cisco AsyncOS is being actively exploited by Chinese state-linked hackers (UAT-9686) since late November...
canonical: https://daily.dev/posts/cisco-zero-day-vulnerability-in-asyncos-exploited-by-chinese-hackers-o1bxv6f8l
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Cisco Zero-Day Vulnerability in AsyncOS Exploited by Chinese Hackers | daily.dev
og:description: A critical zero-day vulnerability (CVE-2025-20393) in Cisco AsyncOS is being actively exploited by Chinese state-linked hackers (UAT-9686) since late November...
og:url: https://daily.dev/posts/cisco-zero-day-vulnerability-in-asyncos-exploited-by-chinese-hackers-o1bxv6f8l
og:image: https://api.daily.dev/og/posts/o1bXv6f8L.png
og:image:alt: Cisco Zero-Day Vulnerability in AsyncOS Exploited by Chinese Hackers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cisco Zero-Day Vulnerability in AsyncOS Exploited by Chinese Hackers

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

A critical zero-day vulnerability (CVE-2025-20393) in Cisco AsyncOS is being actively exploited by Chinese state-linked hackers (UAT-9686) since late November 2025. The flaw affects Cisco Secure Email Gateway and Secure Email and Web Manager appliances with Spam Quarantine enabled, allowing root-level access. Hundreds of systems in India, Thailand, and the US are vulnerable. Attackers deployed Python backdoors, tunneling tools, and log-clearing utilities. Cisco has not released a patch yet but recommends disabling Spam Quarantine, restricting internet access, filtering traffic, and rebuilding compromised systems. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.

## Content

A critical zero-day vulnerability identified as CVE-2025-20393 has been actively exploited by a Chinese state-linked hacking group, UAT-9686, targeting Cisco Secure Email Gateway and Secure Email and Web Manager appliances. The flaw exists in the AsyncOS software, specifically affecting systems with the Spam Quarantine feature enabled and exposed to the internet, allowing attackers to gain root-level access to the devices. This exploitation campaign has been active since late November 2025.

Researchers from the Shadowserver Foundation and Censys have determined that hundreds of systems, primarily located in India, Thailand, and the United States, are potentially vulnerable. Cisco’s investigation revealed that attackers deployed persistence mechanisms such as the AquaShell Python backdoor, tunneling tools like ReverseSSH and Chisel, and log-clearing utilities.

Despite the significant risk posed by this vulnerability, as impacted devices often hold privileged network positions, Cisco has yet to release a patch. In response, affected organizations are advised to take immediate mitigative actions. Cisco recommends disabling the Spam Quarantine feature, restricting internet access to vulnerable systems, filtering traffic through firewalls, and rebuilding compromised appliances to completely remove persistent threats.

Furthermore, the Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-20393 to its Known Exploited Vulnerabilities catalog, emphasizing the urgency for organizations to assess their infrastructures and apply available mitigation strategies. While implementing these recommendations, organizations must also balance remediation efforts with maintaining business continuity until Cisco releases an official patch.

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#python](https://daily.dev/tags/python), [#vulnerability](https://daily.dev/tags/vulnerability), [#cisco](https://daily.dev/tags/cisco)

[View this post on daily.dev](https://daily.dev/posts/cisco-zero-day-vulnerability-in-asyncos-exploited-by-chinese-hackers-o1bxv6f8l)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Cisco Zero-Day Vulnerability in AsyncOS Exploited by Chinese Hackers","url":"https://daily.dev/posts/cisco-zero-day-vulnerability-in-asyncos-exploited-by-chinese-hackers-o1bxv6f8l","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cisco-zero-day-vulnerability-in-asyncos-exploited-by-chinese-hackers-o1bxv6f8l"},"datePublished":"2025-12-18T04:45:10.984Z","dateModified":"2025-12-19T20:17:38.179Z","description":"A critical zero-day vulnerability (CVE-2025-20393) in Cisco AsyncOS is being actively exploited by Chinese state-linked hackers (UAT-9686) since late November...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/855d0ad44080b78025fe704114d53cc8?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/855d0ad44080b78025fe704114d53cc8?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cisco-zero-day-vulnerability-in-asyncos-exploited-by-chinese-hackers-o1bxv6f8l","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,python,vulnerability,cisco","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Cisco Zero-Day Vulnerability in AsyncOS Exploited by Chinese Hackers"}]}
```

