logo

Hackers Exploit Cisco Firepower N-Day Flaws for Unauthorized Access

ID: 17baf8bd-02c6-56f8-832e-2cb238bf055f

STIX ID: report--17baf8bd-02c6-56f8-832e-2cb238bf055f

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Divya

...
...

State-sponsored actor UAT-4356 is actively exploiting two known FXOS vulnerabilities (CVE-2025-20333 and CVE-2025-20362) in Cisco Firepower devices to install a custom backdoor called FIRESTARTER that replaces a WebVPN XML handler in the LINA process to achieve stealthy RCE and persistence across graceful reboots; the advisory provides technical TTPs, IOCs (file paths, process, ClamAV signature, Snort rules) and remediation guidance from Cisco Talos and CISA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.