CISA issues an emergency directive ordering US federal agencies to secure their Cisco firewall devices against two flaws exploited in zero-day attacks
CISA has issued a new emergency directive ordering U.S. federal agencies to secure their Cisco firewall devices against two flaws that have been exploited in zero-day attacks.
BleepingComputerSergiu Gatlan
Context & Ripple Effects
CISA has repeatedly used emergency orders when actively exploited infrastructure flaws require federal action faster than normal patch cycles, including its order to disconnect vulnerable Ivanti VPN appliances and a prior directive on VMware products.
Cisco has also faced an exploited IOS XE zero-day, making this directive part of a recurring exposure of edge and network-management systems rather than an isolated federal compliance event.
First-order effects
U.S. federal agencies must urgently secure affected Cisco firewall devices, shifting security teams from routine vulnerability management to immediate inventory, mitigation and verification work.
Cisco becomes the focal point for remediation guidance and customer support as agencies determine which deployed devices and configurations are exposed.
Second-order effects
The directive gives federal security teams a common escalation trigger, likely concentrating attention on firewall asset visibility and the speed of emergency-change processes.
Other operators using comparable perimeter infrastructure may reassess their own Cisco exposure, while vendors face greater pressure to provide clear, deployable mitigations for actively exploited flaws.
Third-order effects
If emergency directives continue to recur around internet-facing infrastructure, federal cyber policy will increasingly turn vendor vulnerabilities into operational deadlines rather than advisory risk assessments.
The pattern favors security programs that can rapidly map assets to vendor alerts and execute controlled changes; organizations without that capability face greater disruption when zero-days emerge.
The trend: Actively exploited flaws in perimeter and network infrastructure are tightening the link between vulnerability disclosure, vendor response and mandatory federal operational action.
#CyberAlert | Vulnerabilities impacting Cisco ASA and FTD devices The Cyber Centre is aware of exploitation targeting Cisco ASA 5500-X Series devices that run Cisco Secure Firewall ASA software with VPN web services enabled. https://www.cyber.gc.ca/... [image]
Breaking: @CISAgov orders agencies to analyze and patch Cisco networking equipment following the discovery of critical vulnerabilities being exploited by “an advanced threat actor.” https://www.cisa.gov/... Cisco alert: https://sec.cloudapps.cisco.com/ ... [image]
🚨 Cyber threat actors are exploiting newly identified zero-day vulnerabilities in Cisco Adaptive Security Appliances via web services, posing significant risk. Federal agencies must act immediately and follow the guidance in Emergency Directive 25-03. 🔗 https://go.dhs.gov/iAK [im…
❗ALERT❗ We are aware of multiple vulnerabilities impacting Cisco ASA 5500-X Series models. Affected organisations should investigate environments for potential malicious activity and consult Cisco for guidance and mitigation advice. Read the full alert 👉 https://www.cyber.gov.au/…
Heads up: There's a critical vulnerability in Cisco ASA and FTD products that can lead to arbitrary code execution. Unlike many network device vulns that require access to an admin console, this just requires SSL VPN to be enabled on the device. https://sec.cloudapps.cisco.com/ .…
🚨NEW: we issued Emergency Directive 25-03 to address critical vulnerabilities found in Cisco Adaptive Security Appliances & Cisco Firepower Threat Defense devices. Federal agencies must act now, and we urge all orgs to follow the recommended actions: https://go.dhs.gov/iAK [image…
Update: an industry source tells me the hacking group responsible for this activity is likely tied to China. A CISA official said earlier the agency is not focused at the moment on attribution. The high chance that this is China probably wouldn't surprise many. [embedded post]