“`html
Cisco Addresses Critical Vulnerability Exploited by Chinese Threat Actor
Published: 2026/01/19 08:10:18
Cisco has recently released a patch to address a critical vulnerability in its AsyncOS software, which has been actively exploited by a Chinese-nexus threat actor tracked as UAT-9686. The vulnerability affects Cisco’s Secure Email Gateway and Secure Email and Web Manager products, and the threat actor has been deploying a custom persistence mechanism dubbed ‘AquaShell’ alongside tools for reverse tunneling and log purging [1].
Understanding the Vulnerability and the Threat
Cisco Talos, the company’s threat intelligence arm, assesses with moderate confidence that UAT-9686 is responsible for the malicious activity. the vulnerability centers around the Spam Quarantine feature, which, while not enabled by default, can be exposed to the internet. According to Cisco, their deployment guides do not necessitate exposing this feature directly to the internet [[2]].
Why the Delay in Patching?
The patch was released over a month after the initial public warning and seven weeks after the first exploits were detected. While the delay raises concerns, it’s crucial to understand the scope of the vulnerability. It primarily impacts customers who have specifically enabled the Spam
Related reading