CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks. Emergency Directive 25-03 was issued to Federal Civilian Executive Branch (FCEB) agencies on September 25 and requires them to patch CVE-2025-20333 and CVE-2025-20362 vulnerabilities in Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software. "The campaign is widespread and involves exploiting zero-day vulnerabilities to gain unauthenticated remote code execution on ASAs, as well as manipulating read-only memory (ROM) to persist through reboot and system upgrade. This activity presents a significant risk to victim networks," CISA warned today. "CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service." The U.S. cybersecurity agency now requires all FCEB agencies to identify all Cisco ASA and Firepower appliances on their networks, disconnect all compromised devices from the network, and patch those that show no signs of malicious activity by 12 PM EDT on September 26. Additionally, CISA ordered that agencies must permanently disconnect ASA devices that are reaching the end of support by September 30 from their networks. The UK's National Cyber Security Centre (NCSC) says the attackers are targeting 5...
CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
BleepingComputer
·Sergiu Gatlan
·Published Sep 25, 2025
·Updated
Affected Software
2 affected components
Cisco Adaptive Security Appliance
Cisco Firewall Threat Defense
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses CISA's emergency directive for U.S. federal agencies to patch Cisco firewall devices due to recently exploited zero-day vulnerabilities.
2
What security implications are discussed in the article?
The article highlights the security risks posed by two Cisco vulnerabilities that have been actively exploited in attacks.
3
What products or software are affected by the vulnerabilities?
The affected products include Cisco Adaptive Security Appliance and Cisco Firewall Threat Defense.
4
Who issued the emergency directive regarding the Cisco vulnerabilities?
The emergency directive was issued by CISA, the Cybersecurity and Infrastructure Security Agency.
5
What actions are federal agencies required to take according to the article?
Federal agencies are required to secure their Cisco firewall devices by applying patches to address the identified flaws.