# Cisco ASA/FTD flaws exploited with persistent implant

Published: 2026-04-26 · Severity: critical
Canonical: https://vorant.io/reports/a6d15537-06ef-523d-b737-8cfeded6a66e/cisco-asa-ftd-flaws-exploited-with-persistent-implant

> Attackers are chaining Cisco Secure Firewall ASA and FTD vulnerabilities for remote code execution, and the resulting implant can survive patching.

Japan's IPA has reissued a security alert covering vulnerabilities in Cisco Secure Firewall ASA and Cisco Secure FTD that allow remote code execution and denial-of-service when chained with an access-control bypass flaw. IPA confirmed active exploitation in the wild and warned that damage could expand, urging organizations to patch immediately.

## Mentioned in this report

- Vulnerabilities: CVE-2025-20333 (KEV), CVE-2025-20362 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251106.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a6d15537-06ef-523d-b737-8cfeded6a66e/cisco-asa-ftd-flaws-exploited-with-persistent-implant.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
