VORANT. Threat Intelligence Sign in Get the full feed

Cisco ASA/FTD flaws exploited with persistent implant

critical vulnerability

Attackers are chaining Cisco Secure Firewall ASA and FTD vulnerabilities for remote code execution, and the resulting implant can survive patching.

Japan's IPA has reissued a security alert covering vulnerabilities in Cisco Secure Firewall ASA and Cisco Secure FTD that allow remote code execution and denial-of-service when chained with an access-control bypass flaw. IPA confirmed active exploitation in the wild and warned that damage could expand, urging organizations to patch immediately.

Mentioned in this report

Vulnerabilities CVE-2025-20333KEVCVE-2025-20362KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251106.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free