Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogperimeter-device-exposurewidely-deployed-product-advisory

Federal Agencies Face Ongoing Risk from Unpatched Cisco ASA and Firepower Vulnerabilities

Updated 3mo agoFirst seen Nov 12, 20259 sources

CISA has issued updated implementation guidance for Emergency Directive 25-03, highlighting that federal agencies are not fully patching critical vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Firepower devices. Despite previous directives, CISA identified that some agencies reported devices as patched when, in fact, they were still running vulnerable software versions. The vulnerabilities, CVE-2025-20333 and CVE-2025-20362, continue to be actively exploited by advanced threat actors, prompting CISA to urge immediate corrective action and recommend the use of tools like RayDetect to check for evidence of compromise.

The ongoing exploitation campaign has targeted federal civilian agencies since September, with CISA warning that incomplete patching leaves organizations exposed to significant risk. Agencies are directed to verify software versions, apply the minimum required updates, and follow additional mitigation steps if updates were applied after September 26, 2025. CISA has not confirmed whether any agencies have been breached but emphasizes the need for strict compliance to prevent further compromise. All organizations using Cisco ASA and Firepower devices are strongly encouraged to review and implement the latest guidance to mitigate ongoing threats.

Share:
Federal Agencies Face Ongoing Risk from Unpatched Cisco ASA and Firepower Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Nov 13, 20257mo ago

Tens of thousands of Cisco devices remain vulnerable despite guidance

By mid-November 2025, Shadowserver data cited in reporting showed more than 30,000 Cisco devices still vulnerable, down from about 45,000 in early October. The continued exposure indicated that patching and verification efforts remained incomplete across many organizations.

Nov 12, 20257mo ago

CISA adds additional actively exploited flaws to KEV catalog

Alongside the Cisco guidance, CISA added more vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws affecting WatchGuard Firebox, Gladinet Triofox, and the Windows kernel. Federal agencies were given a remediation deadline of December 3, 2025 for these newly listed issues.

CISA warns agencies some devices marked patched remain vulnerable

CISA disclosed that some federal agencies had incorrectly considered Cisco devices remediated even though they were still exposed, due to validation failures and minimum-version requirements. The agency instructed organizations to apply the specific required firmware versions and decommission unsupported hardware.

CISA updates emergency directive guidance for Cisco flaws

On November 12, 2025, CISA updated implementation guidance for its emergency directive covering CVE-2025-20362 and CVE-2025-20333. The agency said some federal agencies had not applied the correct updates and clarified that all ASA and Firepower devices, including non-internet-facing ones, must be remediated within 24 hours under Emergency Directive 25-03.

Nov 5, 20258mo ago

Cisco observes a new attack variant against unpatched devices

Cisco reported a newer attack variant on November 5, 2025 affecting unpatched ASA and Firepower systems. In addition to exploitation, the variant could trigger denial-of-service behavior causing device restarts.

Oct 1, 20259mo ago

More than 45,000 Cisco devices observed exposed in early October

Shadowserver observed roughly 45,000 vulnerable Cisco devices in early October 2025, showing the broad internet exposure of unremediated systems. Later reporting said this number declined but remained in the tens of thousands.

Sep 1, 202510mo ago

Cisco releases fixes for ASA and Firepower zero-day flaws

Cisco issued patches in September 2025 for CVE-2025-20362 and CVE-2025-20333 affecting ASA and Firepower devices. The flaws can be chained to bypass authentication, access restricted endpoints, and achieve remote code execution with full device compromise.

Nov 1, 20233y ago

ArcaneDoor campaign begins targeting government networks

The threat activity later tied to exploitation of Cisco ASA and Firepower vulnerabilities began targeting government networks in November 2023. Multiple reports describe the campaign as ArcaneDoor and attribute it to a state-sponsored, China-linked actor.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

27 LINKEDOpen in app
Malware
1 linked
Organizations
17 linked
Cisco SystemsCISAWatchGuard TechnologiesXcape IncBeyondtrustPalo Alto NetworksStorm-1849Radiant LogicCobaltHackread.comFenix24ShadowServer FoundationSamsungGladinetSamsung ElectronicsFederal Civilian Executive BranchMicrosoft Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.