Cisco ISE Vulnerability Exploited as 0day by APT (Campaign)
ID: bebfe593-5376-5cdf-a357-2c17f90cdda0
STIX ID: report--bebfe593-5376-5cdf-a357-2c17f90cdda0
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-11-13
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Amazon researchers observed an APT actively exploiting zero-day vulnerabilities in Citrix (CVE-2025-5777) and an undocumented Cisco ISE endpoint (CVE-2025-20337) to obtain pre-auth RCE and full administrative control. Attackers deployed a custom in-memory Java web shell disguised as IdentityAuditAction that intercepts HTTP requests and encrypts communications; no IOCs were published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
