Aqueduct Technologies – Advisory
Cisco ASA/FTD Zero-Day Exploitation (ArcaneDoor)
9/26/25 Update:
Cisco has disclosed active exploitation of new zero-day vulnerabilities affecting ASA and Firepower Threat Defense (FTD) firewalls. These attacks are linked to the ongoing ArcaneDoor campaign, which targets internet-exposed VPN and web management services on perimeter firewalls.
NOTE: If you are an Aqueduct Managed Service Customer, we are already creating tickets to identify and schedule a fix for this vulnerability.
WHAT YOU NEED TO KNOW
- The newly identified vulnerabilities include CVE-2025-20333 and CVE-2025-20362 (with CVE-2025-20363 under coordinated disclosure).
- Attackers are using these flaws to gain unauthorized access, execute code, and establish persistence on affected devices.
- Both ASA and FTD are impacted if Remote Access VPN, Clientless SSL VPN, or HTTPS management services are exposed.
- The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has issued an Emergency Directive in response to these threats.
RECOMMENDED ACTIONS
- Apply Cisco’s fixed software updates as soon as they are available for your version and train.
- Cisco has fixed versions listed in a matrix on the official advisory response page linked in the references below.
- This should be considered the primary action to ensure mitigation of these CVSs and avoid device compromise and exposure to persistent threats.
- Restrict exposure via workarounds if needed:
- Disable SSL VPN and legacy web services if not required.
- Restrict HTTPS management access to trusted internal hosts/networks.
- Hunt for compromise: Review Cisco’s Indicators of Compromise (IOCs) and guidance to ensure your devices have not been tampered with.
REFERENCE INFORMATION
- Cisco official advisory and ongoing updates: Cisco ASA/FTD Attacks – Event Response Page
- Cisco Talos blog on ArcaneDoor: ArcaneDoor Threat Campaign
HOW TO GET HELP
Aqueduct is committed to the success of our customers and is ready to assist with resolution of this issue. While we work to proactively reach out to our customers, if you require immediate assistance, please contact us:
- Managed Services Customers – Please contact your Customer Success Manager (CSM) directly for any question regarding our remediation process
- Non-Managed Services Customers – Please reach out to your Account Manager (AM) to discuss options for professional services support.