CISA has issued updated implementation guidance for Emergency Directive 25-03, highlighting that federal agencies are not fully patching critical vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Firepower devices. Despite previous directives, CISA identified that some agencies reported devices as patched when, in fact, they were still running vulnerable software versions. The vulnerabilities, CVE-2025-20333 and CVE-2025-20362, continue to be actively exploited by advanced threat actors, prompting CISA to urge immediate corrective action and recommend the use of tools like RayDetect to check for evidence of compromise.
The ongoing exploitation campaign has targeted federal civilian agencies since September, with CISA warning that incomplete patching leaves organizations exposed to significant risk. Agencies are directed to verify software versions, apply the minimum required updates, and follow additional mitigation steps if updates were applied after September 26, 2025. CISA has not confirmed whether any agencies have been breached but emphasizes the need for strict compliance to prevent further compromise. All organizations using Cisco ASA and Firepower devices are strongly encouraged to review and implement the latest guidance to mitigate ongoing threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
By mid-November 2025, Shadowserver data cited in reporting showed more than 30,000 Cisco devices still vulnerable, down from about 45,000 in early October. The continued exposure indicated that patching and verification efforts remained incomplete across many organizations.
Alongside the Cisco guidance, CISA added more vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws affecting WatchGuard Firebox, Gladinet Triofox, and the Windows kernel. Federal agencies were given a remediation deadline of December 3, 2025 for these newly listed issues.
CISA disclosed that some federal agencies had incorrectly considered Cisco devices remediated even though they were still exposed, due to validation failures and minimum-version requirements. The agency instructed organizations to apply the specific required firmware versions and decommission unsupported hardware.
On November 12, 2025, CISA updated implementation guidance for its emergency directive covering CVE-2025-20362 and CVE-2025-20333. The agency said some federal agencies had not applied the correct updates and clarified that all ASA and Firepower devices, including non-internet-facing ones, must be remediated within 24 hours under Emergency Directive 25-03.
Cisco reported a newer attack variant on November 5, 2025 affecting unpatched ASA and Firepower systems. In addition to exploitation, the variant could trigger denial-of-service behavior causing device restarts.
Shadowserver observed roughly 45,000 vulnerable Cisco devices in early October 2025, showing the broad internet exposure of unremediated systems. Later reporting said this number declined but remained in the tens of thousands.
Cisco issued patches in September 2025 for CVE-2025-20362 and CVE-2025-20333 affecting ASA and Firepower devices. The flaws can be chained to bypass authentication, access restricted endpoints, and achieve remote code execution with full device compromise.
The threat activity later tied to exploitation of Cisco ASA and Firepower vulnerabilities began targeting government networks in November 2023. Multiple reports describe the campaign as ArcaneDoor and attribute it to a state-sponsored, China-linked actor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcecentripetal.ai
Open sourcescworld.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourcecisa.gov
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.