Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

U.S. Cybersecurity Landscape Shaken: CISA Adds Cisco Secure Firewall Flaws to Known Exploited Vulnerabilities Catalog


U.S. Cybersecurity Agency Issues Alert Over Exploited Cisco Firewall Flaws

  • CISA has added two Cisco Secure Firewall vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
  • An advanced threat actor is exploiting zero-day vulnerabilities in Cisco Adaptive Security Appliances, posing a significant risk to victim networks.
  • The two vulnerabilities are CVE-2025-20362 and CVE-2025-20333: one involves missing authorization, and the other a buffer overflow allowing remote code execution.
  • Federal agencies have been issued an emergency directive to identify, mitigate, and update affected devices within specific deadlines.



  • The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert, adding two significant vulnerabilities in Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server to its Known Exploited Vulnerabilities (KEV) catalog. The addition of these flaws underscores the importance of proactive measures being taken by federal agencies and private organizations alike to protect their networks against attacks exploiting these vulnerabilities.

    According to CISA, an ongoing exploitation campaign by an advanced threat actor is targeting Cisco Adaptive Security Appliances (ASA), leveraging zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade. This activity presents a significant risk to victim networks, with CISA indicating that the campaign is connected to an earlier identified threat actor known as ArcaneDoor, who has demonstrated the capability to successfully modify ASA ROM at least as early as 2024.

    The two vulnerabilities in question are CVE-2025-20362 and CVE-2025-20333. The first vulnerability involves a missing authorization flaw in Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server, while the second involves a buffer overflow vulnerability that allows for remote code execution.

    In response to this emerging threat landscape, CISA has issued an emergency directive requiring federal agencies to identify and mitigate potential compromise of Cisco devices. Agencies are ordered to follow specific core dump analysis steps and submit their results by September 26, 2025, while impacted devices must be isolated, and supported devices must be updated within strict deadlines.

    Experts recommend that private organizations review the KEV catalog and address the vulnerabilities in their infrastructure, as these flaws can have far-reaching consequences if left unaddressed. Furthermore, CISA's Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities emphasizes the importance of agencies taking proactive measures to protect their networks against attacks exploiting identified vulnerabilities.

    The addition of these two vulnerabilities highlights the ever-evolving nature of the threat landscape and underscores the need for vigilance and proactive measures in protecting against emerging threats. As CISA continues to monitor this situation, it is essential that organizations prioritize network security and take immediate action to address these vulnerabilities.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-Cybersecurity-Landscape-Shaken-CISA-Adds-Cisco-Secure-Firewall-Flaws-to-Known-Exploited-Vulnerabilities-Catalog-ehn.shtml

  • https://securityaffairs.com/182593/hacking/u-s-cisa-adds-cisco-secure-firewall-asa-and-secure-ftd-flaws-to-its-known-exploited-vulnerabilities-catalog.html

  • https://www.cisa.gov/news-events/alerts/2025/09/25/cisa-directs-federal-agencies-identify-and-mitigate-potential-compromise-cisco-devices

  • https://nvd.nist.gov/vuln/detail/CVE-2025-20362

  • https://www.cvedetails.com/cve/CVE-2025-20362/

  • https://nvd.nist.gov/vuln/detail/CVE-2025-20333

  • https://www.cvedetails.com/cve/CVE-2025-20333/


  • Published: Fri Sep 26 10:22:51 2025 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us