Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Exploring the closed nuclear fuel cycle: From recycling to fuel

Unmasking new TOAD attacks hidden in legitimate infrastructure

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Cisco patches zero-day RCE exploited by China-linked APT in secure email gateway
Identity

Cisco patches zero-day RCE exploited by China-linked APT in secure email gateway

userBy userJanuary 16, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 16, 2026Ravi LakshmananVulnerabilities / Web Security

Cisco patches zero-day RCE

Cisco on Thursday released a security update for maximum severity security flaws affecting Cisco AsyncOS software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager. This comes nearly a month after the company disclosed that it had been attacked by a zero-day attack by a Chinese-aligned Advanced Persistent Threat (APT) attacker codenamed UAT-9686.

The vulnerability, tracked as CVE-2025-20393 (CVSS score: 10.0), is a remote command execution flaw resulting from insufficient validation of HTTP requests by the spam quarantine. Successful exploitation of this flaw could allow an attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.

However, three conditions must be met for the attack to work:

The appliance is running a vulnerable release of Cisco AsyncOS software The appliance is configured with the Spam Quarantine feature The Spam Quarantine feature is exposed to the Internet and is accessible from the Internet

Last month, the networking equipment giant revealed that it had discovered evidence of UAT-9686 exploiting vulnerabilities to drop tunneling tools such as ReverseSSH (also known as AquaTunnel) and Chisel, as well as a log cleaning utility called AquaPurge, as early as late November 2025.

cyber security

This attack is also characterized by the deployment of a lightweight Python backdoor called AquaShell that can receive and execute encoded commands.

In addition to removing the persistence mechanism identified in this attack campaign and installed on the appliance, this vulnerability was addressed in the following versions:

Cisco Email Security Gateway

Cisco AsyncOS Software Release 14.2 and earlier (fixed in 15.0.5-016) Cisco AsyncOS Software Release 15.0 (fixed in 15.0.5-016) Cisco AsyncOS Software Release 15.5 (fixed in 15.5.4-012) Cisco AsyncOS Software Release 16.0 (fixed in 16.0.4-016)

Secure email and web manager

Cisco AsyncOS Software Release 15.0 and earlier (fixed in 15.0.2-007) Cisco AsyncOS Software Release 15.5 (fixed in 15.5.4-007) Cisco AsyncOS Software Release 16.0 (fixed in 16.0.4-010)

Cisco also helps prevent access from unsecured networks, secures the appliance behind a firewall, monitors web log traffic for unexpected traffic to and from the appliance, disables HTTP on the main administrator portal, disables unnecessary network services, and provides strong forms of end-user authentication to the appliance (such as SAML or LDAP). ) and following hardening guidelines for changing the default administrator password to a more secure password.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTaiwan to invest $250 billion in US semiconductor manufacturing
Next Article China-linked APT exploits Sitecore zero-day to attack critical U.S. infrastructure
user
  • Website

Related Posts

Unmasking new TOAD attacks hidden in legitimate infrastructure

January 28, 2026

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

January 28, 2026

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

January 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Exploring the closed nuclear fuel cycle: From recycling to fuel

Unmasking new TOAD attacks hidden in legitimate infrastructure

Fortinet patches CVE-2026-24858 after active FortiOS SSO exploit detected

Everything you need to know about the viral personal AI assistant Clawdbot (now Moltbot)

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.