Cisco ASA/FTD flaws exploited with persistent implant
Attackers are chaining Cisco Secure Firewall ASA and FTD vulnerabilities for remote code execution, and the resulting implant can survive patching.
Japan's IPA has reissued a security alert covering vulnerabilities in Cisco Secure Firewall ASA and Cisco Secure FTD that allow remote code execution and denial-of-service when chained with an access-control bypass flaw. IPA confirmed active exploitation in the wild and warned that damage could expand, urging organizations to patch immediately.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251106.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free