Sunday, August 30, 2026
LIVEGiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
SoftwareAI-assisted

Critical Cisco Vulnerability Let Remote Attackers Execute Arbitrary Code on Firewalls and Routers

Cybersecurity: Cisco Vulnerability Alert Cisco has identified a critical remote code execution vulnerability affecting web services across multiple platforms. The vulnerability, tracked as CVE-2025-20363 (CWE-122), has a CVSS 3.1 Base Score of 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). Impacted software includes ASA, FTD, IOS,…

Critical Cisco Vulnerability Let Remote Attackers Execute Arbitrary Code on Firewalls and Routers

Cybersecurity: Cisco Vulnerability Alert

Cisco has identified a critical remote code execution vulnerability affecting web services across multiple platforms. The vulnerability, tracked as CVE-2025-20363 (CWE-122), has a CVSS 3.1 Base Score of 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). Impacted software includes ASA, FTD, IOS, IOS XE, and IOS XR.

Cisco Input Validation Flaw (CVE-2025-20363)

This vulnerability arises from inadequate validation of user input in HTTP requests. Attackers may exploit this flaw by sending malicious HTTP packets, enabling arbitrary shell command execution as root.

For Cisco Secure Firewall ASA and FTD, exploitation does not require authentication. For IOS, IOS XE, and IOS XR, low-privileged authenticated access is necessary.

Vulnerable services are accessible on SSL or HTTP ports when features like webvpn, AnyConnect SSL VPN, or the HTTP server are active. Successful exploitation could lead to full device compromise.

Cisco has identified a critical remote code execution vulnerability affecting web services across multiple platforms.
Jessica Grant · The Hacking Post

The vulnerability was discovered by Keane O’Kelley of Cisco ASIG, with advisory coordination by ASD, CSE, NCSC, and CISA.

All ASA Series (5500-X, ASAv, Firepower 1000/2100/4100/9000, Secure Firewall 1200/3100/4200), FTD platforms, IOS routers with SSL VPN, IOS XE routers, and ASR 9001 running 32-bit IOS XR with HTTP enabled are affected.

No workarounds are available. Immediate upgrade to fixed software versions is necessary, as detailed in the Cisco advisory.

Advertisement

Risk Assessment

Risk Factors Details
Affected Products Cisco Secure Firewall ASA & FTD Software, Cisco IOS Software & IOS XE Software, Cisco IOS XR Software (32-bit on ASR 9001 with HTTP server enabled)
Impact Remote unauthenticated code execution as root
Exploit Prerequisites SSL VPN (webvpn) or AnyConnect SSL VPN enabled
CVSS 3.1 Score 9.0 (Critical)

Cisco recommends using the Cisco Software Checker to identify vulnerable releases and the earliest available patches. Administrators should audit device configurations to verify SSL VPN or HTTP server status.

For ASA/FTD, confirm webvpn or AnyConnect SSL VPN settings. For IOS XR, ensure the command run uname -s returns Linux or disable the HTTP server with no http server. Cisco PSIRT reports no active exploitation currently.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories