• News/
  • https://www.bleepingcomputer.com/news/security/cisa-warns-feds-to-fully-patch-actively-exploited-cisco-flaws/

CISA warns feds to fully patch actively exploited Cisco flaws

BleepingComputer
·
Sergiu Gatlan
·
Published Nov 13, 2025
·
Updated

CISA warned U.S. federal agencies to fully patch two actively exploited vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Firepower devices. Tracked as CVE-2025-20362 and CVE-2025-20333, these security flaws allow remote threat actors to access restricted URL endpoints without authentication and gain code execution on vulnerable Cisco firewall devices, respectively. If chained, they can enable unauthenticated attackers to gain complete control of unpatched devices remotely. When it patched the two flaws in September, Cisco cautioned customers that they had been exploited as zero-days in attacks targeting 5500-X Series devices with VPN web services enabled. The company also linked these attacks to the ArcaneDoor campaign, which has exploited two other zero-day bugs (CVE-2024-20353 and CVE-2024-20359) to breach government networks since November 2023. The same day, CISA issued Emergency Directive 25-03, ordering U.S. federal agencies to secure their Cisco firewall devices within 24 hours against active exploitation of CVE-2025-20362 and CVE-2025-20333. Internet monitoring platform Shadowserver currently tracks over 30,000 Cisco devices vulnerable to these attacks, down from more than 45,000 when it first began tracking the two vulnerabilities in early October. ​However, as the cybersecurity agency warned today, some government agencies have failed to correctly patch vulnerable devices, leaving them exposed to attacks amid ongoing attacks targeting unpatched Cisco...

Read full article

Affected Software

3 affected components
Cisco Adaptive Security Appliance
Cisco Firepower
Cisco 5500-X Series

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA's warning to federal agencies about patching vulnerabilities in Cisco devices.

2

What security implications are discussed?

The vulnerabilities could allow remote attackers to exploit Cisco Adaptive Security Appliances and Firepower devices.

3

What vulnerabilities are mentioned in the article?

The vulnerabilities are tracked as CVE-2025-20362 and CVE-2025-20333.

4

Which Cisco products are affected by these vulnerabilities?

The affected products include Cisco Adaptive Security Appliance, Cisco Firepower, and Cisco 5500-X Series.

5

What action has CISA recommended for federal agencies?

CISA has recommended that federal agencies fully patch the identified vulnerabilities immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203