Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Cisco ASA/FTD vulnerabilities CVE-2025-20333 and CVE-2025-20362 are still under active exploitation and can be chained for unauthenticated remote control of affected firewalls. CISA has told U.S. federal agencies to fully patch Cisco ASA and Firepower devices, while Emergency Directive 25-03 requires immediate remediation across agency networks. Cisco previously said the flaws were used as zero-days against 5500-X Series devices with VPN web services enabled, and Shadowserver now tracks over 30,000 vulnerable devices.
Related Happenings
CISA BOD 26-04 SharePoint remediation deadline
Public Sector Action
H score77
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector ActionAbout this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector Action
H score35
First: 26.06.2026 22:43
Last: 26.06.2026 22:43
Sources 1
About this happening:
CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector Action
H score46
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
About this happening:
CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector ActionAbout this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector Action
H score33
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
CISA KEV order for Copy Fail on federal Linux devices
Public Sector ActionAbout this happening: CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...
Federal civilian executive branch agency hit by network compromise
Incident
H score21
First: 24.04.2026 23:34
Last: 24.04.2026 23:34
Sources 1
About this happening:
A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Federal civilian executive branch agency hit by network compromise
IncidentAbout this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Timeline
-
24.04.2026 20:06 2 articles · 2mo ago
Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)
Initial DisclosureCVE-2025-20333 and CVE-2025-20362 were exploited in a 2025 campaign against Cisco ASA firmware, giving attackers a route to code execution and restricted-endpoint access on affected appliances.
Show sources
- FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches — thehackernews.com — 24.04.2026 20:06
- FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches — thehackernews.com — 24.04.2026 20:06
-
30.09.2025 19:58 1 articles · 9mo ago
Shadowserver finds 48,800 vulnerable Cisco ASA and FTD instances exposed
Detection Ioc UpdateThreat monitoring by The Shadowserver Foundation found more than 48,800 internet-exposed Cisco Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) instances still vulnerable to CVE-2025-20333 and CVE-2025-20362, including large concentrations in the United States, the United Kingdom, Japan, Germany, Russia, Canada, and Denmark.
Show sources
- Nearly 50,000 Cisco firewalls vulnerable to actively exploited flaws — www.bleepingcomputer.com — 30.09.2025 19:58
-
26.09.2025 08:51 1 articles · 9mo ago
NCSC details RayInitiator and LINE VIPER on Cisco ASA 5500-X devices
Technical Analysis UpdateThe U.K. National Cyber Security Centre (NCSC) said threat actors exploited CVE-2025-20362 and CVE-2025-20333 in zero-day attacks against Cisco ASA 5500-X Series devices, using the RayInitiator GRUB bootkit to load LINE VIPER for command execution, packet captures, VPN AAA bypass, syslog suppression, CLI command harvesting, and delayed reboots.
Show sources
- Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware — thehackernews.com — 26.09.2025 08:51
-
25.09.2025 20:52 2 articles · 9mo ago
CISA issues emergency directive for Cisco ASA and Firepower devices
Legal Policy Action UpdateCISA issued Emergency Directive 25-03 for Federal Civilian Executive Branch agencies, ordering them to inventory Cisco ASA and Firepower devices, collect forensics, disconnect compromised systems, and patch CVE-2025-20333 and CVE-2025-20362 by 12 PM EDT on September 26. The directive also requires agencies to permanently disconnect end-of-support ASA devices by September 30 after zero-day exploitation against Cisco firewall devices.
Show sources
- CISA orders agencies to patch Cisco flaws exploited in zero-day attacks — www.bleepingcomputer.com — 25.09.2025 20:52
- CISA warns feds to fully patch actively exploited Cisco flaws — www.bleepingcomputer.com — 13.11.2025 14:05