Attackers are actively exploiting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) vulnerabilities to compromise internet-facing VPN appliances. CVE-2025-20362, an authentication bypass rated CVSS 6.5, allows unauthenticated access to restricted VPN-related endpoints through crafted HTTP(S) requests when VPN web services are enabled. CERT Polska warned that attackers chain it with CVE-2025-20333 to achieve unauthenticated arbitrary code execution with administrator privileges on vulnerable ASA 5500-X devices. Cisco also disclosed CVE-2025-20363, which permits an authenticated user to execute code as root. CrowdSec reported persistent exploitation activity associated with CVE-2025-20362, tracking 292 attacking IP addresses overall and 2,330 signals in its latest reported 89-day window.
Hunter Strategy attributed exploitation of the three vulnerabilities to the state-aligned ArcaneDoor cluster, also tracked as UAT4356 and Storm-1849. Its report described token harvesting, logging interference, deliberate device crashes, and firmware or ROMMON modifications intended to preserve access through reboots and software upgrades, supporting covert access to VPN sessions and internal networks. Organizations should immediately install Cisco’s fixed releases, using the vendor advisory and Software Checker to select the correct version, and investigate affected devices using CISA’s compromise-checking guidance. Unsupported appliances should be disconnected; suspected persistent compromise warrants boot and firmware integrity checks, with rebuilding or replacement where persistence is confirmed. Detected incidents should be reported to the appropriate national CSIRT.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
The CrowdSec network first observed exploitation of CVE-2025-20362. Its subsequent monitoring recorded continued activity over several months.
CrowdSec released detection coverage for exploitation of the Cisco ASA and FTD VPN authentication-bypass vulnerability.
Security bulletin 36/2025 warned that attackers were chaining CVE-2025-20362 and CVE-2025-20333 to take control of vulnerable Cisco ASA 5500-X devices without authentication. It urged immediate patching, compromise checks using CISA's hunting instructions, and reporting detected incidents to the appropriate national CSIRT.
Cisco released patched ASA and FTD builds addressing the reported vulnerabilities. The applicable fixed release depends on the software branch and can be identified through Cisco's advisories and Software Checker.
Cisco published CVE-2025-20362, an authentication-bypass vulnerability in the ASA and FTD VPN web server. Crafted HTTP(S) requests can allow unauthenticated attackers to access restricted VPN-related endpoints.
The April 2024 ArcaneDoor campaign deployed Line Dancer and Line Runner malware on Cisco ASA appliances. Cisco later assessed with high confidence that the operators behind the newer attacks were responsible for this earlier campaign.
ProjectDiscovery published a detection template for CVE-2025-20362 that was referenced in the vulnerability analysis.
Rapid7 researcher Ryan Emmons published an analysis explaining how crafted requests against the WebVPN path can reach a restricted file-handling endpoint without valid credentials. Rapid7 also described the vulnerability's role in attack chains leading to deeper device compromise.
Hunter Strategy attributed exploitation of CVE-2025-20333, CVE-2025-20362, and CVE-2025-20363 to ArcaneDoor, also tracked as UAT4356 and Storm-1849. The report described firmware and ROMMON persistence, logging interference, and deliberate device crashes, citing Cisco's high-confidence assessment of continuity with the April 2024 operators.
The Hunter Strategy report describes pre-disclosure reconnaissance against internet-facing AnyConnect and WebVPN portals, including automated scanning and fingerprinting before tailored exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
crowdsec.net
Open sourcemoje.cert.pl
Open sourceblog.hunterstrategy.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.