logo

Federal agencies given one day to patch exploited Cisco firewall bugs

ID: fef1c116-dd4d-5b0d-b282-1c8061b9e792

STIX ID: report--fef1c116-dd4d-5b0d-b282-1c8061b9e792

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-09-25

Date Updated: 2026-05-01

...
...

Federal agencies and organizations using Cisco Adaptive Security Appliances are being urged to take immediate action after CISA issued an emergency directive about active exploitation of two critical ASA vulnerabilities (CVE-2025-30333, CVE-2025-20362). Cisco and multiple national cyber agencies link the intrusions to a sophisticated actor associated with the ArcaneDoor campaign; attackers exploited zero-days, achieved persistent access across reboots and upgrades, and used evasion techniques such as disabling logging. Cisco published patches and detailed remediation steps including replacing credentials and resetting compromised devices to factory defaults.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.