Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Cisco ASA 0-Day RCE Flaw Actively Exploited in the Wild

A critical zero-day vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software is being actively exploited.

A critical zero-day vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software is being actively exploited.

Identified as CVE-2025-20333 , this remote code execution flaw allows an authenticated attacker to execute arbitrary code as root on affected devices. Cisco issued an advisory on Tue, Sep 25, 2025, urging users to update immediately to a fixed software release, as no workaround exists.

CVE ID Severity CVSS 3.1 Score CWE

CVE-2025-20333 Critical 9.9 CWE-120

CVE-2025-20362 Medium 6.5 CWE-862

Identified as CVE-2025-20333 , this remote code execution flaw allows an authenticated attacker to execute arbitrary code as root on affected devices.
Peter Collins · Thehackingpost

The vulnerability is located in the VPN web server component of ASA and FTD software, resulting from improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN credentials can send specially crafted requests to the VPN web portal, leading to root privilege escalation and full system compromise.

Another reported medium-severity flaw, CVE-2025-20362, allows unauthenticated attackers to access restricted URL endpoints without proper access checks. While this does not result in code execution, it compromises access controls and could facilitate further attacks.

Affected devices include ASA or FTD systems running a vulnerable release with webvpn or AnyConnect IKEv2 remote access enabled. Specific configurations that open SSL listen sockets, such as crypto ikev2 enable <interface> client-services port <port_numbers> and webvpn enable <interface> , are vulnerable. Cisco Secure Firewall Management Center (FMC) and Device Manager (FDM) configurations enabling remote access VPN also expose FTD devices.

Cisco confirmed that Secure FMC Software is not affected. Users should utilize the Cisco Software Checker to identify affected versions and determine the first fixed release. Upgrade guidance and fixed release numbers are available in the advisory's Fixed Software section. There are no workarounds that fully mitigate these vulnerabilities.

Advertisement

After updating, it is advised to review threat detection settings for VPN services to prevent brute-force login attempts, client initiation attacks, and invalid service connections. Detailed instructions are provided in the Cisco Secure Firewall ASA CLI Configuration Guide under "Configure Threat Detection for VPN Services."

The Cisco PSIRT is tracking active exploitation attempts of CVE-2025-20333 and recommends rapid patching. The vulnerability was discovered during a Cisco TAC support case and is currently being used in the wild. It is crucial for security teams to prioritize patching ASA and FTD devices to prevent potential full-system takeover.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories