Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Warns of Cisco Firewall 0-Day Vulnerabilities Actively Exploited in the Wild

CISA Warns of Cisco Firewall 0-Day Vulnerabilities Actively Exploited in the Wild

Posted on September 26, 2025September 26, 2025 By CWS

CISA has issued an Emergency Directive mandating speedy motion to mitigate two crucial zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, actively exploited in opposition to Cisco Adaptive Safety Home equipment (ASA) and choose Firepower platforms. 

The vulnerabilities permit unauthenticated distant code execution and privilege escalation, enabling superior menace actors to switch read-only reminiscence (ROM) for persistence via reboot and system upgrades.

 Exploit Cisco ASA {Hardware} Zero-Days

CISA hyperlinks this marketing campaign to the ArcaneDoor exercise first recognized in early 2024, throughout which adversaries demonstrated the aptitude to control ASA ROM as early as 2024. 

By exploiting zero-days in ASA {hardware}, ASA-Service Module (ASA-SM), ASA Digital (ASAv), and ASA firmware on Firepower 2100/4100/9300 units, attackers obtain unauthenticated distant code execution. 

Though Safe Boot on Firepower Menace Protection (FTD) home equipment detects ROM manipulation, ASAs lack this safety, making them prime targets.

Cisco has launched safety updates addressing each vulnerabilities:

CVE-2025-20333 permits distant code execution on weak ASAs.

CVE-2025-20362 permits privilege escalation to root-level entry.

Failure to remediate poses an unacceptable threat to federal info programs and significant infrastructure.

CVE IdentifierTitleCVSS 3.1 ScoreSeverityCVE-2025-20333Cisco ASA Distant Code Execution Zero-Day9.8CriticalCVE-2025-20362Cisco ASA Privilege Escalation Zero-Day7.2High

Emergency Directive

For all public-facing ASA {hardware}, carry out CISA’s Core Dump and Hunt Directions Elements 1–3 and submit core dumps through the Malware Subsequent Gen portal by September 26, 2025, 11:59 PM EDT.

If “Compromise Detected,” disconnect (however don’t energy off), report back to CISA, and coordinate incident response. If “No Compromise Detected,” proceed to software program updates or system decommissioning.

Completely disconnect ASA {hardware} with end-of-support on or earlier than September 30, 2025. Businesses unable to conform should apply Cisco-provided software program updates by September 26 and plan for decommissioning.

Obtain and apply the most recent Cisco updates for ASA {hardware} fashions supported via August 31, 2026, and for all ASAv and FTD home equipment by September 26, 2025.

By October 2, 2025, 11:59 PM EDT, submit an entire stock and motion report back to CISA utilizing the offered template. These measures apply to all federal info programs, together with these hosted by third-party suppliers (FedRAMP-authorized or in any other case). 

Businesses stay chargeable for sustaining inventories and making certain compliance. CISA will report cross-agency standing and excellent points to senior management by February 1, 2026.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:0Day, Actively, CISA, Cisco, Exploited, Firewall, Vulnerabilities, Warns, Wild

Post navigation

Previous Post: Chinese State-Sponsored Hackers Attacking Telecommunications Infrastructure to Harvest Sensitive Data
Next Post: No Patches for Vulnerabilities Allowing Cognex Industrial Camera Hacking

Related Posts

Dark Web Scams Mislead with Old Data Leaks Dark Web Scams Mislead with Old Data Leaks Cyber Security News
Critical Windows BitLocker Flaw Poses Security Risk Critical Windows BitLocker Flaw Poses Security Risk Cyber Security News
Christmas Phishing Surge Chains Docusign Spoofing with Identity Theft Questionnaires Christmas Phishing Surge Chains Docusign Spoofing with Identity Theft Questionnaires Cyber Security News
Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics Cyber Security News
Hackers Leverage Multiple Ad Networks to Attack Adroid Users With Triada Malware Hackers Leverage Multiple Ad Networks to Attack Adroid Users With Triada Malware Cyber Security News
Nike Allegedly Hacked by WorldLeaks Ransomware Group Nike Allegedly Hacked by WorldLeaks Ransomware Group Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark