CISCO Security Advisory

Published Date: Not specified

CVE: CVE-2025-20333

Advisory Summary

๐Ÿ“… April 30, 2026

โ— Persisting Threats Against Cisco Secure Firewall ASA and FTD Devices โ€” New Findings from CISA Update

On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an important update to its Emergency Directive 25-03 addressing compromises involving Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) products. The advisory reveals that the ArcaneDoor threat actor has engineered a novel persistence mechanism deeply embedded in the Cisco Firepower eXtensible Operating System (FXOS), the base OS for ASA and FTD installations.

๐Ÿšจ What makes this persistence mechanism particularly challenging is that it survives upgrades to the fixed releases Cisco issued back in September 2025. These prior patches addressed remote code execution and unauthorized access vulnerabilities (CVE-2025-20333 and CVE-2025-20362), which the attackers initially exploited to compromise the systems.

This update serves as a crucial reminder that infrastructure security is a continuously evolving battle, demanding vigilance even after patch deployment.

For detailed technical information and mitigation strategies, refer to Ciscoโ€™s official advisory linked below.

โš™๏ธ Security Impact Rating: Informational

Reference: Vendor Advisory

Leave a Reply

Your email address will not be published. Required fields are marked *