Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 88
2 unique sources, 5 articles

Summary

Hide ▲

Cisco ASA/FTD vulnerabilities CVE-2025-20333 and CVE-2025-20362 are still under active exploitation and can be chained for unauthenticated remote control of affected firewalls. CISA has told U.S. federal agencies to fully patch Cisco ASA and Firepower devices, while Emergency Directive 25-03 requires immediate remediation across agency networks. Cisco previously said the flaws were used as zero-days against 5500-X Series devices with VPN web services enabled, and Shadowserver now tracks over 30,000 vulnerable devices.

Related Happenings

CISA BOD 26-04 SharePoint remediation deadline

Public Sector Action
H score77 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...

CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server

Public Sector Action
H score35 First: 26.06.2026 22:43 Last: 26.06.2026 22:43 Sources 1

About this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...

CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM

Public Sector Action
H score46 First: 26.06.2026 15:31 Last: 26.06.2026 15:31 Sources 1

About this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...

CISA KEV order for Copy Fail on federal Linux devices

Public Sector Action
H score33 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: CISA added Copy Fail to the Known Exploited Vulnerabilities (KEV) Catalog, making the Linux flaw a federal remediation priority. The agency ordered federal agencies*...

Federal civilian executive branch agency hit by network compromise

Incident
H score21 First: 24.04.2026 23:34 Last: 24.04.2026 23:34 Sources 1

About this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...

Timeline

  1. 24.04.2026 20:06 2 articles · 2mo ago

    Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)

    Initial Disclosure

    CVE-2025-20333 and CVE-2025-20362 were exploited in a 2025 campaign against Cisco ASA firmware, giving attackers a route to code execution and restricted-endpoint access on affected appliances.

    Show sources
  2. 30.09.2025 19:58 1 articles · 9mo ago

    Shadowserver finds 48,800 vulnerable Cisco ASA and FTD instances exposed

    Detection Ioc Update

    Threat monitoring by The Shadowserver Foundation found more than 48,800 internet-exposed Cisco Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) instances still vulnerable to CVE-2025-20333 and CVE-2025-20362, including large concentrations in the United States, the United Kingdom, Japan, Germany, Russia, Canada, and Denmark.

    Show sources
  3. 26.09.2025 08:51 1 articles · 9mo ago

    NCSC details RayInitiator and LINE VIPER on Cisco ASA 5500-X devices

    Technical Analysis Update

    The U.K. National Cyber Security Centre (NCSC) said threat actors exploited CVE-2025-20362 and CVE-2025-20333 in zero-day attacks against Cisco ASA 5500-X Series devices, using the RayInitiator GRUB bootkit to load LINE VIPER for command execution, packet captures, VPN AAA bypass, syslog suppression, CLI command harvesting, and delayed reboots.

    Show sources
  4. 25.09.2025 20:52 2 articles · 9mo ago

    CISA issues emergency directive for Cisco ASA and Firepower devices

    Legal Policy Action Update

    CISA issued Emergency Directive 25-03 for Federal Civilian Executive Branch agencies, ordering them to inventory Cisco ASA and Firepower devices, collect forensics, disconnect compromised systems, and patch CVE-2025-20333 and CVE-2025-20362 by 12 PM EDT on September 26. The directive also requires agencies to permanently disconnect end-of-support ASA devices by September 30 after zero-day exploitation against Cisco firewall devices.

    Show sources