Skip to content

CISA urges immediate patching of Cisco ASA and Firepower devices due to active zero

Industrialcyber.Co November 13, 2025

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified ongoing cyber threats targeting Cisco Adaptive Security Appliances (ASA) and Firepower devices and issued new guidance to mitigate zero-day vulnerabilities that persist through reboots and upgrades. The implementation guidance builds on the agency’s September Emergency Directive 25-03, which detailed known vulnerabilities and required immediate mitigation measures. Threat actors continue to exploit these devices, posing significant risks to organizations across sectors.

At the time, CISA determined that CVE-2025-20333, which enables remote code execution, and CVE-2025-20362, which enables privilege escalation, pose an unacceptable risk to federal systems. The lead cybersecurity agency mandates that these vulnerabilities be addressed immediately through the actions outlined in this Directive.

Titled ‘Implementation Guidance for Emergency Directive on Cisco Adaptive Security Appliances (ASA) and Firepower Device Vulnerabilities,’ the CISA guidance provides information on the minimum software versions that address these vulnerabilities and directs federal agencies to conduct corrective patching measures on devices that are not compliant with these requirements. CISA is aware of multiple organizations that believed they had applied the necessary updates but had not, in fact, updated to the minimum software version. CISA recommends that organizations verify that the correct updates are applied.

“By following these best practices, organizations can better protect themselves from potential threats and ensure the integrity of their digital infrastructure,” Nick Andersen, executive assistant director for the cybersecurity division (CSD) at CISA, said in a media statement. “The release of this implementation guidance is a critical step in mitigating the risks posed by these vulnerabilities.”

“In CISA’s analysis of agency-reported data, CISA has identified devices marked as ‘patched’ in the reporting template, but which were updated to a version of the software that is still vulnerable to the threat activity outlined in the ED,” the CISA implementation guidance detailed.

CISA is tracking active exploitation of these vulnerable versions in FCEB agencies. For agencies with Cisco ASA or Firepower devices not yet updated to the necessary software versions or devices that were updated after Sept. 26, 2025, CISA recommends additional actions to mitigate against ongoing and new threat activity. Furthermore, CISA urges agencies with ASAs and Firepower devices to follow this guidance . As a reminder, the ED requires that agencies update all Cisco ASA and Firepower devices, not just public-facing devices, to the latest patch immediately to avoid exploitation.

The implementation guidance noted that fixed releases for Software Train 9.12 and 9.14 are not listed in the Cisco software checker tool but can be accessed through unique links. The fixed release for Cisco Secure ASA Software Release 9.12 is version 9.12.4.72, available through the Cisco Special Release Download. Similarly, the fixed release for Cisco Secure ASA Software Release 9.14 is version 9.14.4.28, also accessible via the Cisco Special Release Download.

This applies to 5512-X and 5515-X, which reached their last date of support on August 31, 2022; 5525-X, 5545-X, and 5555-X, which will reach their last date of support on Sept. 30, 2025; and 5585-X, which reached its last date of support on May 31, 2023.

The CISA mentioned that ED 25-03 requires agencies to update all in-scope Cisco devices to the latest patch within 48 hours of release. Agencies running vulnerable versions of Cisco software must follow CISA’s step-by-step Core Dump and Hunt Instructions (Parts 1–3) for public-facing Cisco ASA hardware devices, submit core dumps through the Malware Gen portal, and patch immediately.

If CISA identifies an agency affected by this issue, it will follow up to confirm that the required actions have been completed. Agencies in this category must also resubmit their ED 25-03 report in CyberScope.

Coinciding with CISA’s implementation guidance, Amazon’s threat intelligence team detected a sophisticated threat actor exploiting previously unknown zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems. The campaign used custom malware and demonstrated access to multiple undisclosed vulnerabilities. This discovery highlights the trend of threat actors focusing on critical identity and network access control infrastructure.

“Our Amazon MadPot honeypot service detected exploitation attempts for the Citrix Bleed Two vulnerability (CVE-2025-5777) prior to public disclosure, indicating a threat actor had been exploiting the vulnerability as a zero-day,” CJ Moses, CISO of Amazon Integrated Security, wrote in an Amazon AWS Security blog post on Wednesday. “Through further investigation of the same threat exploiting the Citrix vulnerability, Amazon Threat Intelligence identified and shared with Cisco an anomalous payload targeting a previously undocumented endpoint in Cisco ISE that used vulnerable deserialization logic. This vulnerability, now designated as CVE-2025-20337, allowed the threat actors to achieve pre-authentication remote code execution on Cisco ISE deployments, providing administrator-level access to compromised systems.”

He added that what made the discovery especially troubling was that active exploitation was already underway before Cisco had even assigned a CVE number or released full patches for all affected Cisco ISE branches. “This patch-gap exploitation technique is a hallmark of sophisticated threat actors who closely monitor security updates and quickly weaponize vulnerabilities.”

Moses warned that critical infrastructure components such as identity management platforms and remote access gateways continue to be top targets for threat actors, underscoring the need for heightened vigilance by security teams. The pre-authentication nature of these exploits reveals that even well-configured and meticulously maintained systems can be affected. This underscores the importance of implementing comprehensive defense-in-depth strategies and developing robust detection capabilities that can identify unusual behavior patterns.

Amazon recommends limiting access, through firewalls or layered access, to privileged security appliance endpoints such as management portals.

Last week, CISA revealed critical vulnerabilities affecting systems from Fuji Electric, Delta Electronics, Survision, Radiometrics, and IDIS, raising fresh security concerns across the industrial sector.