The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive following the discovery of an active exploitation campaign targeting Cisco Adaptive Security Appliances (ASA) and Cisco Firepower Threat Defense (FTD) devices.
According to CISA and Cisco, an advanced threat actor is exploiting previously unknown (“zero-day”) vulnerabilities to gain remote access and persistence on affected Cisco devices.
These vulnerabilities are tracked as:
- CVE-2025-20333 – Remote Code Execution
- CVE-2025-20362 – Privilege Escalation
Affected Platforms:
Cisco ASA (hardware, virtual, and service modules), Cisco ASA firmware on Firepower 2100/4100/9300 series, and Cisco Firepower Threat Defense (FTD) appliances.
Recommended Actions:
- Upgrade to the latest available Cisco firmware.
- Disconnect or decommission any end-of-support (EoS) devices.
- Monitor for unusual outbound traffic or configuration changes.
Learn More
For additional background, please refer to the official CISA directive:
CISA Emergency Directive ED 25-03 – Identify and Mitigate Potential Compromise of Cisco ASA and FTD Devices
If you would like assistance verifying your environment or applying mitigations, please contact GoSecure today.



