CISA urges immediate patching of Cisco ASA and Firepower devices due to active zero-day exploits – Industrial Cyber

CISA urges immediate patching of Cisco ASA and Firepower devices due to active zero-day exploits – Industrial Cyber

By Anna Ribeiro
Publication Date: 2025-11-13 13:58:00

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified ongoing cyber threats targeting Cisco Adaptive Security Appliances (ASA)  and Firepower devices and issued new guidance to mitigate zero-day vulnerabilities that persist through reboots and upgrades. The implementation guidance builds on the agency’s September Emergency Directive 25-03, which detailed known vulnerabilities and required immediate mitigation measures. Threat actors continue to exploit these devices, posing significant risks to organizations across sectors.

At the time, CISA determined that CVE-2025-20333, which enables remote code execution, and CVE-2025-20362, which enables privilege escalation, pose an unacceptable risk to federal systems. The lead cybersecurity agency mandates that these vulnerabilities be addressed immediately through the actions outlined in this Directive. 

Titled ‘Implementation Guidance for Emergency Directive on Cisco Adaptive Security…