CVE-2025-20333

Confirmed PUBLISHED

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense...

Cisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.9 Critical EPSS 40.4%

At a Glance

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.

cisa edge
CVE Published
Sep 25, 2025
Exploitation Reported
Jun 01, 2026
CVSS
9.9 Critical
EPSS
40.4%
Remote Low complexity No user interaction

Affected Versions

300 version rows · page 7 of 12

Vendor Product Version Status
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.16.4.70

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.16.4.71

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.16.4.76

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.16.4.82

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.16.4.84

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.7

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.9

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.10

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.11

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.13

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.15

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.20

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.30

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.33

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.17.1.39

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.1

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.1.3

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.2

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.2.5

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.2.7

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.2.8

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.3

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.3.39

Affected
Cisco
Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

9.18.3.46

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.