• News/
  • https://www.bleepingcomputer.com/news/security/cisa-orders-agencies-to-patch-cisco-flaws-exploited-in-zero-day-attacks/

CISA orders agencies to patch Cisco flaws exploited in zero-day attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 25, 2025
·
Updated

CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks. Emergency Directive 25-03 was issued to Federal Civilian Executive Branch (FCEB) agencies on September 25 and requires them to patch CVE-2025-20333 and CVE-2025-20362 vulnerabilities in Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software. "The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade. This activity presents a significant risk to victim networks," CISA warned today. "CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service." The U.S. cybersecurity agency now requires all FCEB agencies to identify all Cisco ASA and Firepower appliances on their networks, disconnect all compromised devices from the network, and patch those that show no signs of malicious activity by 12 PM EDT on September 26. Additionally, CISA ordered that agencies must permanently disconnect ASA devices that are reaching the end of support by September 30 from their networks. The UK's National Cyber Security Centre (NCSC) says the attackers are targeting 5...

Read full article

Affected Software

2 affected components
Cisco Adaptive Security Appliance
Cisco Firewall Threat Defense

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA's emergency directive for U.S. federal agencies to patch Cisco firewall devices due to recently exploited zero-day vulnerabilities.

2

What security implications are discussed in the article?

The article highlights the security risks posed by two Cisco vulnerabilities that have been actively exploited in attacks.

3

What products or software are affected by the vulnerabilities?

The affected products include Cisco Adaptive Security Appliance and Cisco Firewall Threat Defense.

4

Who issued the emergency directive regarding the Cisco vulnerabilities?

The emergency directive was issued by CISA, the Cybersecurity and Infrastructure Security Agency.

5

What actions are federal agencies required to take according to the article?

Federal agencies are required to secure their Cisco firewall devices by applying patches to address the identified flaws.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203