VORANT. Threat Intelligence Sign in Get the full feed

Cisco ASA and FTD flaws exploited in wild

critical vulnerability

Cisco Secure Firewall ASA and FTD contain remote code execution and access control vulnerabilities being actively exploited in combination to deploy persistent backdoors.

Japan's IPA has issued an urgent security alert for Cisco Secure Firewall ASA and Cisco Secure Firewall Threat Defense (FTD) products. The vulnerabilities include a remote code execution flaw and an access control bypass that, when chained together, allow remote attackers to execute arbitrary code and cause denial of service. Active exploitation has been confirmed in the wild.

In an April 2026 update, Cisco disclosed that compromised devices may contain persistent mechanisms that allow attackers to maintain access even after patching. Organizations that have been breached must rebuild affected systems rather than simply applying updates. Cisco has released fixed versions and published indicators of compromise to help organizations detect intrusions.

IPA urges immediate patching for all affected Cisco firewall deployments and recommends consulting Cisco's guidance on breach detection and system reconstruction for any potentially compromised devices.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251106.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free