Threat actors have increasingly targeted remote access technologies in 2025 by exploiting a series of critical vulnerabilities, many of which were zero-days at the time of discovery. Security researchers have identified several high-impact vulnerabilities affecting widely deployed enterprise products, including Citrix NetScaler, Cisco IOS and IOS XE, Cisco ASA and FTD, Fortra GoAnywhere MFT, and Oracle E-Business Suite. These vulnerabilities have enabled remote code execution, authentication bypass, and other forms of unauthorized access, posing significant risks to organizations relying on these technologies for perimeter defense. Notably, some of these flaws, such as CVE-2025-7775 in Citrix NetScaler and CVE-2025-20352 in Cisco IOS/IOS XE, were exploited before public disclosure, highlighting the persistent threat of zero-day attacks. The threat actor group UAT4356, also known as ArcaneDoor, has been linked to the exploitation of certain Cisco vulnerabilities, demonstrating the involvement of sophisticated adversaries. In addition to newly discovered zero-days, attackers continue to leverage older, unpatched vulnerabilities, underscoring the ongoing challenge of maintaining effective patch management. Initial access brokers and both opportunistic and targeted threat actors have been observed using these exploits to gain footholds in enterprise environments, often as a precursor to further malicious activity such as extortion or data theft. Security bulletins from vendors like Ivanti and Fortinet have been referenced to provide guidance and mitigation steps for affected organizations. The prevalence of public proof-of-concept exploits for some vulnerabilities has accelerated their weaponization in the wild. The impact of these attacks is amplified by the critical role remote access technologies play in modern enterprise infrastructure, making timely detection and remediation essential. Security teams are urged to prioritize patching, monitor for signs of exploitation, and implement robust access controls to mitigate risk. The ongoing exploitation of both new and old vulnerabilities highlights the need for continuous vigilance and proactive security measures. Researchers emphasize the importance of machine-readable, well-vetted vulnerability intelligence to support rapid response. The trend of targeting remote access solutions is expected to persist, given their attractiveness as initial access vectors. Organizations are advised to review vendor advisories and apply recommended patches without delay. The evolving threat landscape requires a coordinated effort between vendors, security researchers, and enterprise defenders to reduce exposure and limit the impact of these attacks.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
In response to ongoing exploitation campaigns in 2025, CISA added affected vulnerabilities to its advisory and known-exploited-vulnerability tracking lists to warn defenders and drive remediation.
Reporting on 2025 exploitation of remote access technologies linked some intrusions to the China-nexus threat group APT41, alongside broader opportunistic and targeted activity by cybercriminals and initial access brokers.
Across 2025, attackers actively exploited vulnerabilities in remote access and perimeter technologies from vendors including Ivanti, Fortinet, SonicWall, Sophos, Palo Alto Networks, Juniper, Citrix, Cisco, and Check Point for initial access.
VulnCheck reported assigning 60 new CVEs in September 2025 as part of coordinated vulnerability disclosure efforts intended to surface previously untracked risks.
During September 2025, VulnCheck added 54 newly exploited CVEs to its Known Exploited Vulnerabilities list, noting that many were not yet present on CISA's KEV catalog.
CVE-2025-61882 in Oracle E-Business Suite was reported as being mass exploited in 2025 as part of the same late-summer to early-fall wave of attacks against major enterprise software.
CVE-2025-10035 in Fortra GoAnywhere MFT saw mass exploitation in 2025, with reporting linking activity to threat groups including Storm-1175, Graceful Spider, and Cl0p in attacks and extortion campaigns.
Between late August and early October 2025, multiple high-impact zero-day vulnerabilities began to be disclosed and exploited across enterprise products including Citrix NetScaler, Cisco IOS/ASA/FTD, Fortra GoAnywhere MFT, and Oracle E-Business Suite.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.