
- Cisco patches critical RCE flaw (CVE-2025-20393) in Secure Email appliances
- Chinese state-sponsored groups exploited it for weeks using Aquashell and tunneling tools
- Updates remove persistence mechanisms; extent of global compromise remains unknown
A maximum-severity vulnerability in certain Cisco products has finally been addressed after allegedly being exploited by Chinese hackers for several weeks.