Cisco firewalls are facing a new wave of attacks – here’s what we know about these latest issues


  • Attackers exploit two zero days in Cisco ASA firewalls for remote access and persistence
  • The campaign uses stealth tactics such as disabling logs and tampering with firmware to evade detection.
  • Cisco recommends upgrading Secure Boot compatible models and completely resetting compromised devices

Cisco is warning customers of an ongoing campaign against businesses using some of its services, after recently becoming aware of a “new attack variant.”

In a new report, the company said it observed an ongoing campaign targeting Cisco ASA 5500-X Series and Secure Firewall devices. Attackers are exploiting two critical zero-day vulnerabilities, identified as CVE-2025-20333 and CVE-2025-20362, which could allow them to remotely access, execute arbitrary code, deploy malware, and sometimes even cause denial of service (DoS) reboots on unpatched devices.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top