Skip to content
VulniPulse
Highest advisory severityUnrated Exploited CISA KEV 1 vendor · 1 advisory

CVE-2025-20362

CVE-2025-20362: 1 tracked advisory record across Cisco. CISA KEV listed; exploitation observed. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityUnrated

    Advisory [CVE-2025-20333 +1] Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

    cisco-sa-asaftd-persist-CISAED25-03Source published Source updated

    This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. According to the update, the ArcaneDoor threat actor has developed a previously unknown persistence mechanism that is preserved across upgrading to the fixed releases that were published in September 2025. This persistence mechanism resides in the Cisco Firepower eXtensible Operating System (FXOS) Software base operating system for Cisco Secure Firewall ASA Software and Cisco Secure FTD Software installations on the affected hardware platforms. Note: According to the…

    Related products — impact not confirmed
    • ASA
    • Secure Firewall
    • FTD
    • Firepower
    Source-reported affected versions
    • Release 9.16 (first fixed: 9.16.4.92)
    • Release 9.18 (first fixed: 9.18.4.135)
    • Release 9.20 (first fixed: 9.20.4.30)
    • Release 9.22 (first fixed: 9.22.3.5)

    20 more entries in the full advisory.

    Source-reported fixed versions
    • 9.16.4.92
    • 9.18.4.135
    • 9.20.4.30
    • 9.22.3.5

    20 more entries in the full advisory.

    Mitigation guidance
    • Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products.
    • According to the update, the ArcaneDoor threat actor has developed a previously unknown persistence mechanism that is preserved across upgrading to the fixed releases that were published in September 2025.
    Workarounds
    • To fully remove the persistence mechanism, Cisco strongly recommends reimaging and upgrading the device using the fixed releases that are listed in the Fixed Software section of this advisory. For more information, see the reimaging documentation for the specific product:
    • Cisco Secure Firewall ASA and Threat Defense Reimage Guide
    • Perform a Complete Reimage for FXOS in Firepower 4100 and 9300 Series
    • Reimage a Secure FTD for 1000, 2100, and 3100 Series

    5 more entries in the full advisory.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery