Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

CISA warns exploited Cisco flaws are a serious risk, so patch now

Tech Wavo by Tech Wavo
November 14, 2025
in Computers
0



  • CISA warns agencies failed to properly patch two actively exploited Cisco firewall vulnerabilities
  • CVE-2025-20333 and CVE-2025-20362 were linked to the ArcaneDoor campaign targeting government networks
  • Over 32,000 devices remain vulnerable despite emergency directives and patching efforts

The US Cybersecurity and Infrastructure Security Agency (CISA) is warning Federal Civilian Executive Branch agencies (FCEB) that some of them failed to properly patch two important Cisco vulnerabilities being actively exploited in the wild.

As a result, these agencies continue to be at risk of malware, infostealer, and possibly even ransomware attacks.

The two flaws in question are tracked as CVE-2025-20333, and CVE.2025-20362, discovered in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) software in September 2025.


You may like

Mistakes in patching

At the time, Cisco said that both were exploited as zero-days to target 5500-X Series devices with web services enabled.

The company stressed the attacks were linked to the ArcaneDoor campaign that’s been active for years, going after government networks.

The same day, CISA issued an emergency directive, giving federal agencies just 24 hours to patch up or stop using the vulnerable software. Usually, when CISA adds a bug to its Known Exploited Vulnerabilities (KEV) catalog, it gives a three-week deadline for patching.

However, it seems that some agencies did not properly patch their systems up and thus remained vulnerable.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“CISA is aware of multiple organizations that believed they had applied the necessary updates but had not in fact updated to the minimum software version,” the agency said in an updated advisory, published on November 12, 2025.

“CISA recommends all organizations verify the correct updates are applied. For agencies with ASA or Firepower devices not yet updated to the necessary software versions or devices that were updated after September 26, 2025, CISA recommends additional actions to mitigate against ongoing and new threat activity. CISA urges all agencies with ASAs and Firepower devices to follow this guidance.”

The Shadowserver Foundation currently tracks around 32,000 vulnerable devices, down from almost 40,000 a month ago. Progress, but slow.

Via BleepingComputer


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Previous Post

Switch 2 bundles, Switch game deals, discounted accessories and more

Next Post

WhatsApp to launch third-party chat integration in Europe soon

Next Post
WhatsApp’s new AI feature lets you rephrase and adjust the tone of your messages

WhatsApp to launch third-party chat integration in Europe soon

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Apple COO Jeff Williams is now officially retired

by Tech Wavo
November 15, 2025
0
Apple COO Jeff Williams is now officially retired
Technology

On Friday, Apple Chief Operating Officer Jeff Williams clocked out for the last time at Apple Park, and is now...

Read more

Once-in-a-Century Growth in Energy Demand

by Tech Wavo
November 15, 2025
0
Once-in-a-Century Growth in Energy Demand
Financial

 Can you describe how institutional investors' appetite for clean, renewable energy has evolved over the years and why solar is...

Read more

I’ll eat my hat if there’s a better cheap phone deal than this one before Black Friday

by Tech Wavo
November 15, 2025
0
I’ll eat my hat if there’s a better cheap phone deal than this one before Black Friday
Computers

When my colleague described the Motorola Edge 60 as “the best cheap phone tested in years” and “as good as...

Read more

Global internet freedoms deteriorated (again) in 2025 – Germany, Georgia & US lost ground

by Tech Wavo
November 15, 2025
0
Global internet freedoms deteriorated (again) in 2025 – Germany, Georgia & US lost ground
Computers

Internet freedoms have declined in 2025 for the 15th consecutive yearHalf of the 18 countries ranked as 'Free' have experienced...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock