Friday, October 2, 2026

Cisco ASA 0-Day RCE Flaw Actively Exploited in the Wild

A critical zero-day vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software is being actively exploited in the wild.

Tracked as CVE-2025-20333, this remote code execution flaw allows an authenticated attacker to execute arbitrary code as root on affected devices.

Cisco published an advisory on September 25, 2025, urging all users to update immediately to a fixed software release. No workaround exists.

CVE IDSeverityCVSS 3.1 ScoreCWE
CVE-2025-20333Critical9.9CWE-120
CVE-2025-20362Medium6.5CWE-862

Cisco identified the issue in the VPN web server component of ASA and FTD software. The flaw results from improper validation of user-supplied input in HTTP(S) requests.

An attacker with valid VPN credentials can send specially crafted requests to the VPN web portal and trigger code execution. Successful exploitation grants root privileges, leading to full system compromise.

In addition to the critical RCE, Cisco also reported a medium-severity flaw, CVE-2025-20362. This issue permits unauthenticated attackers to access restricted URL endpoints without proper access checks.

While this does not directly lead to code execution, it undermines access controls and could serve as a stepping stone for further attacks.

Cisco’s advisory (cisco-sa-asaftd-webvpn-z5xP8EUB) includes detailed information and links to software updates.

The advisory ID is cisco-sa-asaftd-webvpn-z5xP8EUB, and the Cisco Bug ID is CSCwq79831. Both vulnerabilities share similar root causes in input validation for HTTP(S) services.

Affected devices include any ASA or FTD system running a vulnerable release with webvpn or AnyConnect IKEv2 remote access enabled.

Specific configurations that open SSL listen sockets, such as crypto ikev2 enable <interface> client-services port <port_numbers> and webvpn enable <interface>, are at risk.

Cisco Secure Firewall Management Center (FMC) and Device Manager (FDM) configurations that enable remote access VPN also expose FTD devices.

Cisco has confirmed that Secure FMC Software is not affected. Customers should use the Cisco Software Checker to identify affected versions and determine the first fixed release.

Upgrade guidance and fixed release numbers are available in the advisory’s Fixed Software section.

Cisco strongly recommends that customers upgrade to the fixed software release as soon as possible. There are no workarounds that fully mitigate these vulnerabilities.

After updating, review threat detection settings for VPN services to guard against brute-force login attempts, client initiation attacks, and invalid service connections.

Detailed instructions appear in the Cisco Secure Firewall ASA CLI Configuration Guide under “Configure Threat Detection for VPN Services.”

The Cisco PSIRT is tracking active exploitation attempts of CVE-2025-20333 and encourages rapid patching.

This vulnerability was discovered during a Cisco TAC support case and is being used in the wild.

Security teams should prioritize patching ASA and FTD devices to prevent potential full-system takeover.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF

A newly released PlayStation 5 jailbreak chain, called Relapse,...

Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root

Two critical vulnerabilities in the open-source Zammad helpdesk and...

Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations

Safari's History database contains a lesser-known tagging artifact that...

Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion

A publicly exposed attacker staging server has provided a...

Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking

cPanel has released security updates to address three vulnerabilities...

Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust

A critical vulnerability in Capacitor, identified as CVE-2026-103922, could...

OpenAI Blocks 15,000 Requests Trying to Extract Protected Model Reasoning

OpenAI has disrupted a coordinated campaign to extract protected...

Related Articles

Recent News