patch&proof.
← The dispatch

perimeter / Source brief

Cisco tied an active firewall campaign to a chained set of flaws

Cisco said evidence strongly indicated attackers used CVE-2025-20333 and CVE-2025-20362 in attacks against Secure Firewall ASA and FTD devices. A companio…

Historical backfill · prepared 16 September 2026. Dates below describe the source or event; this is a local review edition.

Cisco tied an active firewall campaign to a chained set of flaws.

What happened. Cisco said evidence strongly indicated attackers used CVE-2025-20333 and CVE-2025-20362 in attacks against Secure Firewall ASA and FTD devices. A companion web-services flaw, CVE-2025-20363, was also disclosed.

Impact and confidence

High confidence in the vendor’s observed exploitation statement; the full scope and actor identity were not established in the public response. Internet-facing security appliances remained the immediate concern.

Defensive takeaway

Confirm appliance model and software release, assign the upgrade, preserve relevant evidence, and verify that management interfaces are not publicly exposed.

Evidence & dates

Follow the source.

Preserved from the earlier sourced news desk. This brief is distinct from the newly researched historical articles.

Source published
2025-09-25
Event date
2025-09-25
Site publication
Unpublished · local review
Cisco Event Response: Continued Attacks Against Cisco Firewalls
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval