Cisco has issued a critical security warning regarding two zero-day vulnerabilities actively exploited in its Adaptive Security Appliance (ASA) firewalls. These vulnerabilities allow attackers to execute remote code and potentially take full control of affected devices, posing significant risks to network security. The flaws, identified as CVE-2024-20016 and CVE-2024-20017, have been leveraged in targeted attacks, emphasizing the urgency for organizations to apply patches and mitigations promptly. Cisco's advisory details the attack vectors, impact, and recommended remediation steps to protect infrastructure from these exploits. This incident highlights the persistent threat landscape targeting firewall devices, which are crucial for perimeter defense in enterprise environments. Security teams are urged to prioritize updates and monitor for indicators of compromise related to these zero-days to prevent potential breaches and data loss.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 25 Sep 2025 16:50:13 +0000