LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-20362: Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 25, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 26, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-20362 to its Known Exploited Vulnerabilities catalog on Sep 25, 2025, with a federal patch deadline of Sep 26, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be…

CVE-2025-20362 is a missing authorization vulnerability in the VPN web server component of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software. Because these products commonly sit at the network edge and terminate remote-access VPN sessions, an unauthenticated or under-authorized attacker who can reach the VPN web interface may be able to perform actions that should require proper authorization. The issue can also be chained with CVE-2025-20333, increasing the potential impact. Organizations that rely on ASA or FTD for perimeter security should treat this as a high-priority review item and confirm exact exposure against Cisco’s advisory.

How it works

The flaw is classified as CWE-862 (Missing Authorization). In essence, the VPN web server fails to enforce authorization checks on certain requests. An attacker who can send traffic to the exposed VPN web service may invoke functionality or obtain information that the product design intends only for authorized users. Public detail on the precise request paths or parameters is limited; defenders should not assume a particular exploit technique and must rely on the vendor advisory for the authoritative description. Because the component is network-facing, successful abuse could allow an attacker to pivot further, especially if the vulnerability is combined with the related issue CVE-2025-20333. No public evidence of ransomware campaigns leveraging this CVE has been documented.

Am I affected? How to find it in your systems

Cisco ASA and FTD appliances are typically deployed as firewalls, VPN concentrators, or threat-defense gateways at internet edges, data-center perimeters, or remote-access hubs. Inventory every device running ASA or FTD software that has the VPN web server (AnyConnect or clientless SSL VPN) enabled and reachable from untrusted networks.

If the device is managed as a cloud service, also follow the applicable BOD 22-01 guidance referenced by CISA.

How to remediate

Apply the software update that Cisco has released for this vulnerability. Obtain the exact image names and upgrade paths from the official Cisco advisory and follow the vendor’s installation and verification procedures. After patching, re-validate that the VPN web server is running the corrected code and that authorization checks are functioning as expected.

Once the patch is applied, re-enable any temporary compensating controls only if they remain necessary for defense-in-depth.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface and increase detection.

Federal civilian executive branch agencies must also follow the mitigation steps and timelines set out in CISA Emergency Directive 25-03 and the related KEV guidance.

If your data may have been exposed

Actively exploited edge vulnerabilities can lead to unauthorized access and subsequent data exposure. If you suspect compromise, isolate the affected appliance, preserve forensic logs, rotate credentials that may have been accessible through the VPN portal, and engage your incident-response process. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to determine whether any of your credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
WeaknessCWE-862
Added to CISA KEVSep 25, 2025
Federal patch deadlineSep 26, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities