Cisco ASA and FTD Firewall RCE
ID: 3b54fb8a-eaf6-589e-a824-ac3b942c71ca
STIX ID: report--3b54fb8a-eaf6-589e-a824-ac3b942c71ca
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
A sophisticated espionage campaign is actively exploiting critical zero-day vulnerabilities in Cisco Secure Firewall ASA and FTD (CVE-2025-20333, CVE-2025-20362, CVE-2025-20363) to achieve unauthenticated remote code execution and ROM-level persistence; activity is attributed to an advanced actor tracked as ArcaneDoor (UAT4356/Storm-1849), has triggered CISA Emergency Directive ED 25-03, and organizations are urged to follow vendor advisories and mitigation guidance immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
