Two critical zero-day vulnerabilities in Cisco ASA and FTD software are being actively exploited by the ArcaneDoor threat group. CVE-2025-20333 allows authenticated remote code execution, while CVE-2025-20362 enables unauthenticated access to restricted endpoints. CISA issued Emergency Directive ED 25-03 requiring federal agencies to patch within 24 hours, as attackers are chaining these flaws to bypass authentication and persist through ROM manipulation.

3m read timeFrom thehackernews.com
Post cover image
Table of contents
CISA Issues Emergency Directive ED 25-03 #

Sort: