Back to list

Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense — CISCO-SA-ASAFTD-PERSIST-CISAED25-03

Cisco · Cisco · CISCO-SA-ASAFTD-PERSIST-CISAED25-03

ID
CISCO-SA-ASAFTD-PERSIST-CISAED25-03
Date
Source
Cisco
Vendor
Cisco
Threat
medium

Summary

On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. According to the update, the ArcaneDoor threat actor has developed a previously unknown…

Timeline

Published by source
2026-05-19

Risk context

  • Reported severity or threat level: medium.
  • Review exposure for the affected product or family: Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense.

Product

Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

What to do

General, cautious steps (verify details in the official source):

  • Review exposure and plan remediation based on risk and environment.
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Evidence and provenance

Canonical advisory ID
CISCO-SA-ASAFTD-PERSIST-CISAED25-03
Source
Cisco
Vendor
Cisco
Published by source
2026-05-19
Last source activity
2026-05-19
Additional identifiers
CVE-2025-20333
Curated by
hlukh.ch

Related advisories and connections

These advisories are connected by shared CVE, product, vendor, source, or time signals.