# Cisco ASA and FTD flaws exploited in wild

Published: 2026-04-26 · Severity: critical
Canonical: https://vorant.io/reports/a6d15537-06ef-523d-b737-8cfeded6a66e/cisco-asa-and-ftd-flaws-exploited-in-wild

> Cisco Secure Firewall ASA and FTD contain remote code execution and access control vulnerabilities being actively exploited in combination to deploy persistent backdoors.

Japan's IPA has issued an urgent security alert for Cisco Secure Firewall ASA and Cisco Secure Firewall Threat Defense (FTD) products. The vulnerabilities include a remote code execution flaw and an access control bypass that, when chained together, allow remote attackers to execute arbitrary code and cause denial of service. Active exploitation has been confirmed in the wild.

In an April 2026 update, Cisco disclosed that compromised devices may contain persistent mechanisms that allow attackers to maintain access even after patching. Organizations that have been breached must rebuild affected systems rather than simply applying updates. Cisco has released fixed versions and published indicators of compromise to help organizations detect intrusions.

IPA urges immediate patching for all affected Cisco firewall deployments and recommends consulting Cisco's guidance on breach detection and system reconstruction for any potentially compromised devices.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251106.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a6d15537-06ef-523d-b737-8cfeded6a66e/cisco-asa-and-ftd-flaws-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
