Cisco finally fixes AsyncOS zero-day exploited since November
Overview
Cisco has addressed a serious vulnerability in its AsyncOS software that has been exploited since November 2025. This zero-day flaw specifically affects Secure Email Gateway (SEG) appliances, which are used by organizations to filter and protect email traffic. Attackers have been able to exploit this weakness, putting sensitive data at risk and potentially compromising email communications for users relying on these appliances. The timely patch is crucial for organizations to secure their email systems and prevent further exploitation. Companies using these SEG appliances should prioritize applying the update to safeguard against these attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Cisco Secure Email Gateway (SEG) appliances running AsyncOS.
- Action Required: Cisco has released a patch for AsyncOS to fix the zero-day vulnerability.
- Timeline: Ongoing since November 2025
Original Article Summary
Cisco finally patched a maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway (SEG) appliances since November 2025. [...]
Impact
Cisco Secure Email Gateway (SEG) appliances running AsyncOS.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since November 2025
Remediation
Cisco has released a patch for AsyncOS to fix the zero-day vulnerability. Users should immediately update their SEG appliances to the latest version provided by Cisco to mitigate the risk of exploitation.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Zero-day, Cisco, Exploit, and 3 more.