Cisco has disclosed a critical zero-day remote code execution (RCE) vulnerability affecting its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) products. This vulnerability allows unauthenticated attackers to execute arbitrary code on vulnerable devices, potentially leading to full system compromise. The flaw resides in the way these devices handle certain network packets, enabling attackers to exploit the issue remotely without requiring user interaction. Cisco has released security advisories urging users to apply mitigations and patches promptly to protect their networks from exploitation. This vulnerability poses a significant risk to organizations relying on Cisco ASA and FTD for network security, emphasizing the need for immediate action to prevent potential breaches. The cybersecurity community is actively monitoring the situation as threat actors may attempt to weaponize this vulnerability in targeted attacks. Users are advised to follow Cisco's guidance and implement recommended security measures to safeguard their infrastructure.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 06 Nov 2025 09:15:26 +0000