Cisco has disclosed multiple critical zero-day vulnerabilities affecting its Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software, which are actively being exploited in the wild. The vulnerabilities, tracked as CVE-2025-20362 and CVE-2025-20333, impact the VPN web server component of these devices and can lead to remote code execution or unauthorized access. According to Cisco's advisory, CVE-2025-20362 allows unauthenticated, remote attackers to access restricted URL endpoints without authentication by sending specially crafted HTTP requests. CVE-2025-20333, on the other hand, enables authenticated attackers with valid VPN credentials to execute arbitrary code as root, potentially resulting in full device compromise. CISA has responded by adding both vulnerabilities to its Known Exploited Vulnerabilities Catalog and issuing an emergency directive (ED 25-03) that requires federal agencies to identify, analyze, and mitigate any potential compromises immediately. The vulnerabilities stem from improper validation of user-supplied input in HTTP(S) requests, making it possible for attackers to bypass security controls. Cisco has provided a list of vulnerable configurations, including those using AnyConnect IKEv2 Remote Access with client services enabled. The CVE-2025-20333 vulnerability is rated as critical with a CVSS score of 9.9, underscoring the severity of the threat. Exploitation of these flaws could allow attackers to gain root-level access, execute arbitrary code, and take full control of affected devices. The vulnerabilities affect a wide range of Cisco products, including ASA, FTD, and potentially IOS, IOS XE, and IOS XR software, as described in related advisories. Cisco has urged all customers to apply patches immediately to prevent exploitation. The vulnerabilities are being actively targeted, increasing the urgency for organizations to remediate affected systems. Attackers exploiting these flaws could use compromised devices as entry points into broader enterprise networks. The technical details highlight the importance of proper input validation in web services exposed to the internet. Organizations are advised to review their firewall configurations and ensure that all relevant updates are applied. The rapid response from CISA and Cisco reflects the high risk posed by these vulnerabilities to both public and private sector networks. Security teams should monitor for signs of compromise and follow Cisco's mitigation guidance to reduce exposure. The incident demonstrates the ongoing threat posed by zero-day vulnerabilities in widely deployed network security appliances.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
CISA disclosed that a U.S. federal civilian agency's Cisco Firepower device running ASA software had been compromised in September 2025 with the FIRESTARTER backdoor, which remained on the device even after patches were applied. CISA and the UK NCSC said FIRESTARTER is part of a broader campaign exploiting CVE-2025-20333 and CVE-2025-20362 and warned that patching alone may not remove the malware from already compromised systems.
Cisco published a new security advisory describing the continued evolution of a persistence mechanism used against Secure Firewall ASA and FTD devices. The advisory indicates attackers refined post-compromise persistence beyond the techniques previously documented in 2025, adding new technical detail for defenders.
By early October 2025, threat research reports said attackers were chaining the Cisco flaws with brute-force activity, disabling logging, installing backdoors, and in some cases modifying firmware, underscoring the severity of compromise and recovery challenges.
By September 30 and October 1, 2025, multiple outlets reported that nearly 50,000 Cisco firewalls were still vulnerable despite active exploitation warnings and available fixes, showing limited patch uptake and ongoing risk.
As of September 29, 2025, Shadowserver scans identified more than 48,800 internet-exposed Cisco ASA and FTD appliances that remained vulnerable, with the largest concentration in the United States.
On 2025-09-26, Finland’s National Cyber Security Centre warned about the actively exploited Cisco ASA and FTD vulnerabilities and said it had already contacted hundreds of domestic organizations that may be running affected versions. The notice urged rapid patching and investigation for compromise, noting some attacks deploy persistence that can survive patching.
The UK NCSC reported that attackers exploiting the Cisco devices were deploying a shellcode loader called Line Viper followed by a GRUB bootkit named RayInitiator, adding technical detail on post-exploitation activity.
Following disclosure of the active exploitation, CISA issued an emergency directive requiring FCEB agencies to check for compromise and rapidly upgrade affected Cisco devices. The directive also required end-of-support ASA devices to be disconnected by the end of the month.
On September 26, 2025, CERT-EU published advisory 2025-036 warning about critical vulnerabilities in Cisco ASA and FTD and urging affected organizations to remediate quickly.
Cisco published fixes and related detection guidance for the ASA and FTD vulnerabilities, with reporting noting exploitation had begun before patches were available. Advisories urged rapid upgrading because the flaws could enable unauthenticated access and arbitrary code execution.
On September 25, 2025, Cisco and multiple security advisories disclosed critical vulnerabilities affecting Cisco ASA and FTD, including CVE-2025-20333 and CVE-2025-20362, and stated they were being exploited in the wild.
On September 4, 2025, GreyNoise warned that the observed Cisco ASA scanning could be tied to emerging or undocumented vulnerabilities, raising early concern before public patching guidance was available.
GreyNoise reported suspicious scanning activity targeting Cisco ASA devices in late August 2025, indicating possible reconnaissance or early exploitation activity against yet-undisclosed flaws.
15 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesec.cloudapps.cisco.com
Open sourcecentripetal.ai
Open sourcehelpnetsecurity.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcecvefeed.io
Open sourcetenable.com
Open sourcecisecurity.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.