Cisco Patches Critical Zero-Day Vulnerability in Email Security Gateway

“`html



<a href="https://www.netacad.com/cybersecurity" title="What is Cybersecurity? | Free Courses and Resources - Networking Academy" rel="noopener">Cisco</a> Addresses Critical ‌Vulnerability Exploited by Chinese Threat Actor

Cisco Addresses Critical Vulnerability‌ Exploited ​by Chinese ⁤Threat Actor

Published: 2026/01/19 08:10:18

Cisco has recently released a patch to address a‌ critical vulnerability in its AsyncOS software, ⁢which has been actively exploited ⁣by a Chinese-nexus threat actor tracked as UAT-9686. The vulnerability affects Cisco’s Secure Email ‍Gateway and Secure Email and Web Manager products, and the threat actor has been deploying a⁤ custom persistence mechanism dubbed ‘AquaShell’ alongside tools for​ reverse tunneling and log purging [1].

Understanding ​the Vulnerability and the⁣ Threat

Cisco Talos, the company’s threat intelligence arm, assesses with ‍moderate confidence that UAT-9686 is responsible for ⁣the malicious activity. the vulnerability centers around the Spam Quarantine​ feature, which, while not enabled by default, can⁤ be ⁢exposed to the internet.⁤ According to ⁢Cisco, their deployment guides do not necessitate exposing this⁢ feature directly to the internet [[2]].

Why the Delay in Patching?

The ‌patch was⁢ released over a month after the initial public warning and seven weeks after the first exploits were detected. While the delay raises concerns, ​it’s crucial⁤ to ​understand the scope of⁢ the vulnerability. It primarily impacts ⁣customers who⁢ have specifically enabled the Spam

Leave a Comment