Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense — CISCO-SA-ASAFTD-PERSIST-CISAED25-03
Cisco · Cisco · CISCO-SA-ASAFTD-PERSIST-CISAED25-03
CISCO-SA-ASAFTD-PERSIST-CISAED25-03
Cisco
Cisco
medium
Summary
On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. According to the update, the ArcaneDoor threat actor has developed a previously unknown…
Timeline
- Published by source
- 2026-05-19
Risk context
- Reported severity or threat level: medium.
- Review exposure for the affected product or family: Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense.
Product
Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
What to do
General, cautious steps (verify details in the official source):
- Review exposure and plan remediation based on risk and environment.
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.
Official advisory
Evidence and provenance
- Canonical advisory ID
- CISCO-SA-ASAFTD-PERSIST-CISAED25-03
- Source
- Cisco
- Vendor
- Cisco
- Published by source
- 2026-05-19
- Last source activity
- 2026-05-19
- Additional identifiers
- CVE-2025-20333
- Curated by
- hlukh.ch
Related advisories and connections
These advisories are connected by shared CVE, product, vendor, source, or time signals.