HomeSecurityCISA: Requires Cisco to fix zero-day vulnerabilities

CISA: Requires Cisco to patch zero-day vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Administration (CISA) has issued a new emergency directive (25-03) calling on all federal agencies to immediately secure Cisco firewall devices . The order was issued on September 25 and concerns Cisco’s Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software , where two critical vulnerabilities have been identified : CVE-2025-20333 and CVE-2025-20362 .

Cisco CISA

According to CISA, the vulnerabilities are already being actively exploited in zero-day attacks, allowing remote code execution and maintaining malicious control even after system reboots or upgrades.

See also: Sophisticated malware campaign targets WordPress websites

What CISA asks of federal agencies

CISA requires all federal FCEB agencies to:

  • map all Cisco ASA and Firepower devices in their networks,
  • collect forensic data and assess potential violations,
  • permanently disconnect devices that are no longer supported,
  • install the latest security patches on any devices that remain in use.

Initial actions must be completed by September 26, while the final withdrawal of old devices must be done by September 30.

The role of the NCSC and new malicious tools

The UK’s National Cyber ​​Security Centre (NCSC) confirms that hackers are targeting Cisco 5500-X series without Secure Boot enabled. Attackers are installing specialized tools, such as the malicious RayInitiator bootkit, which can survive even after firmware updates. This tool allows for the installation of additional malware, command execution and possible data extraction.

CISA: Requires Cisco to patch zero-day vulnerabilities

At the same time, the use of the LINE VIPER shellcode loader is also mentioned , which allows for low-level compromise and makes it difficult to detect the attack by conventional analysis tools.

Cisco Vulnerabilities: The Connection to the ArcaneDoor Campaign

Cisco and CISA are linking the new attacks to the extensive ArcaneDoor, which was revealed in 2024. At that time, the UAT4356 (also known as STORM-1849 at Microsoft) exploited other zero-days in ASA and FTD devices to infiltrate government networks worldwide.

See also: NVIDIA Merlin vulnerability allows remote code execution

ArcaneDoor was characterized by the use of highly advanced techniques, such as Line Dancer (in-memory shellcode loader) and Line Runner (persistent backdoor), which ensured long-term persistence of attackers in critical networks.

How the new combination of vulnerabilities works

Cisco explained that CVE-2025-20333 could allow attackers with valid credentials to execute code remotely, while CVE-2025-20362 allows access to restricted URL endpoints without authentication.

When the two vulnerabilities are exploited in combination, complete control of a device is possible with virtually no hindrance. Cisco researchers observed that attackers are implementing sophisticated obfuscation methods, such as:

  • disabling recording mechanisms,
  • interception of CLI commands,
  • Intentional shutdown of devices to prevent incident analysis.
CISA: Requires Cisco to patch zero-day vulnerabilities

New patches and additional vulnerability

Cisco announced the release of emergency updates that fix the two zero-day vulnerabilities. It also fixed a third critical vulnerability (CVE-2025-20363) in Cisco IOS and firewall software, which could also allow remote code execution.

However, the company clarified that the third vulnerability does not appear to be related to current attacks, nor is there any evidence that it has been exploited by malicious actors.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: BMC vulnerabilities allow bypass of Signature Verification

What does it mean for the public and private sectors?

CISA's intervention shows how critical the problem is: government networks are at risk from sophisticated campaigns that aim to remain undetected for a long time. For the private sector, the case serves as a warning:

  • organizations must implement updates in a timely manner,
  • to utilize secure boot mechanisms on their devices,
  • and maintain alternative operating plans in the event of a breach.

The speed with which these attacks are evolving highlights the need for continued collaboration between government agencies, technology vendors, and businesses.

New zero-day attacks against Cisco ASA and FTD firewalls demonstrate how targeted cybercrime has become on critical infrastructure. With CISA enforcing urgent measures and Cisco rushing to fix the gaps, the ArcaneDoor case appears to be continuing with new episodes. The message is clear: a lack of immediate action can leave the most protected networks exposed to threats that are evolving faster than ever.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS