Cisco tied an active firewall campaign to a chained set of flaws.
What happened. Cisco said evidence strongly indicated attackers used CVE-2025-20333 and CVE-2025-20362 in attacks against Secure Firewall ASA and FTD devices. A companion web-services flaw, CVE-2025-20363, was also disclosed.
Impact and confidence
High confidence in the vendor’s observed exploitation statement; the full scope and actor identity were not established in the public response. Internet-facing security appliances remained the immediate concern.
Defensive takeaway
Confirm appliance model and software release, assign the upgrade, preserve relevant evidence, and verify that management interfaces are not publicly exposed.