The Cybersecurity and Infrastructure Security Agency (CISA) has issued Emergency Directive ED 25-03 in response to the active exploitation of two zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices. These vulnerabilities, tracked as CVE-2025-20333 and CVE-2025-20362, have been added to CISA’s Known Exploited Vulnerabilities Catalog due to their critical nature and ongoing exploitation in the wild. CVE-2025-20333 allows authenticated remote attackers to execute arbitrary code on affected devices, while CVE-2025-20362 enables unauthenticated attackers to access restricted URL endpoints. The exploitation campaign is widespread, with attackers leveraging these flaws to gain persistent, unauthorized access to federal networks, including manipulating device memory to survive reboots and upgrades. CISA has mandated that all federal agencies identify every instance of Cisco ASA and Firepower devices in their environments, collect and transmit memory files for forensic analysis, and follow specific procedures to assess potential compromise. Agencies are required to disconnect any compromised or end-of-support devices and to patch all unaffected devices by a strict deadline. Cisco has released security updates to address these vulnerabilities and has strongly recommended immediate upgrades to fixed software releases. The directive also includes detailed eviction strategies and forensic tools to assist agencies in containment and remediation efforts. The campaign has been linked to sophisticated threat activity, with references to the 2024 ArcaneDoor campaign and persistent malware such as RayInitiator and LINE VIPER. International cybersecurity agencies, including those from the UK, Australia, and Canada, have collaborated with Cisco and CISA in investigating and responding to these attacks. Security researchers observed a significant uptick in reconnaissance activity targeting Cisco ASA login portals and Telnet/SSH services in the weeks leading up to the disclosure, indicating a coordinated and large-scale threat. CISA’s directive underscores the significant risk posed to federal networks and the urgency of immediate mitigation actions. Agencies are also required to permanently disconnect ASA devices that are reaching end-of-support status by the end of September. The incident highlights the ongoing threat to network infrastructure devices and the importance of rapid, coordinated response to zero-day exploitation. Cisco’s advisories and CISA’s directive provide comprehensive technical guidance for detection, containment, and remediation. The situation remains dynamic, with ongoing forensic analysis and monitoring for further malicious activity. Organizations outside the federal government are also strongly advised to review their exposure and apply relevant patches and mitigations. The collaborative response demonstrates the criticality of public-private partnerships in addressing advanced cyber threats targeting core network infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-23, CISA published a malware analysis report on FIRESTARTER, a remote-access malware family found on Cisco Firepower and Secure Firewall products running ASA or FTD software after exploitation of CVE-2025-20333 and CVE-2025-20362. CISA said it detected the malware during monitoring of federal civilian agency devices, warned that patching alone might not remove the threat due to persistence, and updated Emergency Directive 25-03 with new response actions.
On September 26, 2025, security vendors including Unit 42 and Eclypsium published threat analysis and defensive guidance on the active exploitation of the Cisco ASA flaws. These reports helped clarify exposure conditions, compromise risks, and mitigation priorities for defenders.
On September 26, 2025, the UK NCSC reported that attackers had exploited the Cisco firewall zero-days to deploy two previously undocumented malware families, RayInitiator and LINE VIPER. NCSC described RayInitiator as a persistent GRUB bootkit capable of surviving reboots and firmware upgrades, with LINE VIPER acting as a user-mode shellcode loader.
By September 26, 2025, multiple government cybersecurity agencies including the UK NCSC and the Canadian Centre for Cyber Security publicly urged organizations to patch affected Cisco products without delay. Their warnings reflected concern that the flaws were under active exploitation beyond U.S. federal networks.
On September 25, 2025, CISA ordered U.S. federal civilian agencies to identify, patch, or disconnect affected Cisco ASA and Firepower devices under Emergency Directive 25-03. The directive also required agencies to assess devices for signs of compromise and remove unsupported end-of-life ASA systems from networks.
On September 25, 2025, CISA added CVE-2025-20333 and CVE-2025-20362 to its Known Exploited Vulnerabilities catalog. The listing formally recognized the flaws as actively exploited and increased pressure on organizations to remediate quickly.
Alongside its advisories, Cisco said the zero-day exploitation was part of the ArcaneDoor campaign and credited the Australian Cyber Security Centre, the Canadian Centre for Cyber Security, the UK NCSC, and CISA for investigative assistance. The company said the attacks affected ASA and FTD devices and urged customers to upgrade immediately.
On September 25, 2025, Cisco published advisories for CVE-2025-20333, CVE-2025-20362, and CVE-2025-20363 and released fixed software. Cisco confirmed the first two flaws were being exploited in the wild and warned they could be chained to achieve remote code execution on affected ASA and FTD devices.
In late August 2025, GreyNoise reported campaigns involving up to 25,000 unique IPs targeting ASA login portals and Cisco IOS Telnet/SSH services. The activity was described as the kind of reconnaissance that often precedes public vulnerability disclosure.
Cisco said it began investigating a state-sponsored campaign in May 2025 affecting ASA 5500-X devices with VPN web services enabled. The intrusions enabled malware implantation, command execution, and possible data exfiltration while using anti-forensic techniques such as disabling logging and crashing devices.
Cisco and CISA said the ArcaneDoor campaign had been targeting government and telecom networks globally since at least November 2023. The activity was later linked to a sophisticated state-sponsored threat cluster tracked as UAT4356 / STORM-1849.
22 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourceeclypsium.com
Open sourceunit42.paloaltonetworks.com
Open sourcego.theregister.com
Open sourcecybersecuritydive.com
Open sourcecyberscoop.com
Open sourcesecurityaffairs.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.