Key Takeaways
- 1.Chinese hackers are actively exploiting a zero-day vulnerability in Cisco products.
- 2.Hundreds of Cisco customers are at risk due to this campaign.
- 3.The vulnerability affects several Cisco products, including Secure Email Gateway and Secure Email and Web Manager.
- 4.Cisco recommends rebuilding affected appliances as the primary remediation step.
- 5.There are currently no patches available to fix the vulnerability.
Cisco customers are under siege. Security researchers have uncovered a new hacking campaign, backed by the Chinese government, targeting users of popular Cisco products. The attackers are exploiting a recently discovered zero-day vulnerability, putting potentially hundreds of organizations at risk. This article will delve into the details of the attack, the affected systems, and what steps users can take to protect themselves.
The Discovery and the Threat
On Wednesday, December 17, 2025, Cisco revealed that a group of Chinese government-backed hackers had discovered and were actively exploiting a zero-day vulnerability within their enterprise products. The vulnerability, officially designated as CVE-2025-20393, allows attackers to compromise systems using products such as Cisco's Secure Email Gateway and Secure Email and Web Manager. A zero-day vulnerability is a flaw in software that is known to the attackers before the vendor has a patch available to fix it, making it extremely dangerous.
Piotr Kijewski, the chief executive of the Shadowserver Foundation, a non-profit organization dedicated to monitoring the internet for malicious activity, stated that the scale of potential exposure is in the hundreds of affected customers, not the thousands. The foundation is tracking vulnerable systems on their dashboard. Shadowserver has a page to keep track of the number of affected systems.
Products at Risk
The vulnerability exists in software used by several Cisco products, notably the Secure Email Gateway and the Secure Email and Web Manager. These products are vulnerable if they are reachable from the internet and have the “spam quarantine” feature enabled, though Cisco notes neither of these settings are enabled by default, which may explain why the number of affected systems is not larger. However, the potential for exploitation remains significant.
No Patches Available and Remediation Steps
A critical aspect of this situation is the absence of an available patch. Cisco's security advisory, which can be found in its security advisory, strongly advises customers to rebuild affected appliances to a secure state. According to Cisco's threat intelligence arm, Talos, the campaign has been active since at least late November 2025.
Rebuilding is currently the only viable method to remove the persistence mechanisms used by the threat actors. Until a patch is released, this is the main action users need to do to avoid being compromised. In the absence of a patch, this is the most prudent course of action to protect against further attacks.
Who is Affected?
While the exact number of affected customers remains uncertain, estimates from Shadowserver and Censys, another cybersecurity firm, show that the impact is not insignificant. Censys has observed 220 internet-exposed Cisco email gateways, confirming the presence of vulnerable systems. The United States, India, and Thailand have dozens of vulnerable systems located within their borders.
The Threat Actors
Cisco's report attributes the campaign to Chinese government-backed hackers, pointing to a sophisticated and well-resourced adversary. The exact identity of the group is not yet publicly known, but the sophistication of the attack and the potential targets suggest a highly skilled and determined group.
The Importance of Cybersecurity Best Practices
This incident underscores the importance of strong cybersecurity practices. Organizations must continuously monitor their systems for vulnerabilities, apply security patches promptly, and implement robust security measures to protect themselves from attacks. The ongoing attacks highlight that cybersecurity is an ongoing process, requiring constant vigilance and proactive measures. It's critical to stay informed of threats by visiting resources like the Cybersecurity & Infrastructure Security Agency (CISA).
Conclusion
The exploitation of a zero-day vulnerability by Chinese hackers targeting Cisco customers is a serious threat. With no patches immediately available, organizations using the affected Cisco products must take immediate action to mitigate the risk. Rebuilding the affected appliances is the recommended course of action for now. As this situation develops, it is important to stay updated on the latest information from Cisco and other reputable cybersecurity sources.
Frequently Asked Questions (FAQs)
Q: What is a zero-day vulnerability? A: A zero-day vulnerability is a software flaw that is discovered and exploited by attackers before the vendor has a chance to create and release a patch to fix it. This makes it particularly dangerous because there is no immediate fix available.
Q: Which Cisco products are affected? A: The vulnerability affects Cisco's Secure Email Gateway and Secure Email and Web Manager, specifically if they are reachable from the internet and have the spam quarantine feature enabled.
Q: What should I do if my organization uses these Cisco products? A: Cisco recommends rebuilding affected appliances to a secure state. Monitor security advisories from Cisco and other reputable cybersecurity sources for updates.
Q: How can I stay informed about this threat? A: Regularly check Cisco's security advisories and follow updates from cybersecurity news outlets. Also, monitor the Shadowserver Foundation's tracking page for real-time information. Visit websites such as MITRE to stay up-to-date on vulnerability information and cybersecurity best practices.
Q: Is there any other way to protect my systems? A: Besides the rebuild, ensure that the spam quarantine feature, if enabled, is configured with strong access controls and that all network traffic is monitored for suspicious activity. Make sure you use a firewall.
Topics covered:
#Security