Cisco ASA and IOS/IOS XE zero-day exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Cisco's exploitation wave spans both ASA and IOS/IOS XE. On Sep. 25, 2025, CISA issued an Emergency Directive over ongoing attacks against Cisco ASA devices, warning of unauthenticated remote code execution and persistence tied to ArcaneDoor. A day later, Cisco and Trend Micro said CVE-2025-20352 in Cisco IOS Software and Cisco IOS XE was being abused in Operation Zero Disco to install Linux rootkits on older switches, including 9400, 9300, and legacy 3750G models.
Related Happenings
Cisco Secure Workload REST API validation/authentication flaw (CVE-2026-20223)
Vulnerability
H score49
First: 21.05.2026 15:04
Last: 21.05.2026 15:04
Sources 1
About this happening:
Cisco Secure Workload Cluster Software was patched for CVE-2026-20223, a critical REST API flaw that could let attackers gain Site Admin privileges and cross tenan...
Cisco Secure Workload REST API validation/authentication flaw (CVE-2026-20223)
VulnerabilityAbout this happening: Cisco Secure Workload Cluster Software was patched for CVE-2026-20223, a critical REST API flaw that could let attackers gain Site Admin privileges and cross tenan...
Cisco ThousandEyes and Nexus security patches
Security Patch Release
H score31
First: 21.05.2026 15:04
Last: 21.05.2026 15:04
Sources 1
About this happening:
Cisco released patches for three medium-severity vulnerabilities affecting ThousandEyes Virtual Appliance, ThousandEyes Enterprise Agent, and Nexus 3000/9000 switche...
Cisco ThousandEyes and Nexus security patches
Security Patch ReleaseAbout this happening: Cisco released patches for three medium-severity vulnerabilities affecting ThousandEyes Virtual Appliance, ThousandEyes Enterprise Agent, and Nexus 3000/9000 switche...
Cisco Catalyst SD-WAN authentication bypass flaw actively exploited (CVE-2026-20182)
Vulnerability
H score60
First: 14.05.2026 23:09
Last: 14.05.2026 23:09
Sources 1
About this happening:
CVE-2026-20182 is an actively exploited authentication bypass in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, creating a path to administr...
Cisco Catalyst SD-WAN authentication bypass flaw actively exploited (CVE-2026-20182)
VulnerabilityAbout this happening: CVE-2026-20182 is an actively exploited authentication bypass in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, creating a path to administr...
Latest development: 14.05.2026 23:25
Cisco released a patch for CVE-2026-20182, giving organizations using Cisco Catalyst SD-WAN Controllers a way to block the authentication bypass before UAT-8616 can continue using it for administrative access, SSH key insertion, NETCONF changes, and root escalation.
Cisco security patch release for CVE-2026-20188
Security Patch Release
H score35
First: 06.05.2026 21:06
Last: 06.05.2026 21:06
Sources 1
About this happening:
Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...
Cisco security patch release for CVE-2026-20188
Security Patch ReleaseAbout this happening: Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...
Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)
Vulnerability
H score88
First: 24.04.2026 20:06
Last: 24.04.2026 20:06
Sources 1
About this happening:
Cisco ASA/FTD vulnerabilities CVE-2025-20333 and CVE-2025-20362 are still under active exploitation and can be chained for unauthenticated remote control of af...
Cisco ASA/FTD code execution and authentication bypass flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Cisco ASA/FTD vulnerabilities CVE-2025-20333 and CVE-2025-20362 are still under active exploitation and can be chained for unauthenticated remote control of af...
Timeline
-
16.10.2025 21:13 1 articles · 9mo ago
Operation Zero Disco exploits Cisco IOS and IOS XE switches
Exploitation ObservedTrend Micro says attackers in Operation Zero Disco exploited CVE-2025-20352 in older Cisco IOS and IOS XE networking devices, including Cisco 9400, 9300, and legacy 3750G series devices, to deploy a Linux rootkit and gain persistent access; the activity also included attempts to abuse CVE-2017-3881 on Cisco switches lacking endpoint detection response solutions.
Show sources
- Hackers exploit Cisco SNMP flaw to deploy rootkit on switches — www.bleepingcomputer.com — 16.10.2025 21:13
-
25.09.2025 22:22 2 articles · 9mo ago
CISA issues Emergency Directive on Cisco ASA zero-days
Legal Policy Action UpdateCISA issues an Emergency Directive on ongoing activity targeting Cisco Adaptive Security Appliances (ASA), saying a state-sponsored APT tied to ArcaneDoor is exploiting zero-day vulnerabilities to gain unauthenticated remote code execution and persist through reboot and system upgrade by manipulating ROM; the directive cites CVE-2025-20333, CVE-2025-20363, and CVE-2025-20362, and requires federal civilian agencies to disconnect end-of-support devices and upgrade remaining systems by 11:59 PM EST on September 26, 2025.
Show sources
- Cisco's Wave of Actively Exploited Zero-Day Bugs Targets Firewalls, IOS — www.darkreading.com — 25.09.2025 22:22
- Cisco's Wave of Actively Exploited Zero-Day Bugs Targets Firewalls, IOS — www.darkreading.com — 25.09.2025 22:22
-
24.09.2025 03:00 2 articles · 9mo ago
Cisco discloses CVE-2025-20352 in IOS and IOS XE
Initial DisclosureCisco discloses CVE-2025-20352, a CVSS 7.7 SNMP subsystem flaw in Cisco IOS Software and Cisco IOS XE that can enable authenticated remote code execution and denial of service when SNMP is enabled and the affected object ID is not excluded; Trend Micro estimates at least 2 million devices may be at risk, and Cisco urges customers to upgrade to a fixed release such as IOS XE 17.15.4a or apply the advisory mitigation by disabling affected object identifiers.
Show sources
- Cisco's Wave of Actively Exploited Zero-Day Bugs Targets Firewalls, IOS — www.darkreading.com — 25.09.2025 22:22
- Hackers Deploy Linux Rootkits via Cisco SNMP Flaw in "Zero Disco' Attacks — thehackernews.com — 16.10.2025 14:38