24h | 7d | 30d

Overview

  • Cisco
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

25 Sep 2025
Published
26 Feb 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
50.69%

Description

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory. A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to access restricted URL endpoints that are related to remote access VPN that should otherwise be inaccessible without authentication. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: FIRESTARTER Backdoor

APT actors deployed FIRESTARTER, a persistent Linux backdoor on Cisco Firepower and Secure Firewall devices via CVE-2025-20333 and CVE-2025-20362. The malware survives firmware patches and works with LINE VIPER to maintain remote access. Any organization running these devices is at risk of undetect…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Cisco
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

25 Sep 2025
Published
26 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
41.43%

Description

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: FIRESTARTER Backdoor

APT actors deployed FIRESTARTER, a persistent Linux backdoor on Cisco Firepower and Secure Firewall devices via CVE-2025-20333 and CVE-2025-20362. The malware survives firmware patches and works with LINE VIPER to maintain remote access. Any organization running these devices is at risk of undetect…

threatnoir.com/focus

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Python Software Foundation
  • CPython
  • http.client

10 Apr 2026
Published
21 Apr 2026
Updated

CVSS v4.0
MEDIUM (5.7)
EPSS
0.06%

KEV

Description

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
CVE-2026-1502 (HTTP injection) and CVE-2026-4786 (command injection) hit Python 3.14 on Fedora. Don't just patch today. Build automation that finds ANY CVE. Read -> tinyurl.com/2krzcetb #Fedora #Security
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Python Software Foundation
  • CPython

13 Apr 2026
Published
14 Apr 2026
Updated

CVSS v4.0
HIGH (7.0)
EPSS
0.02%

KEV

Description

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
CVE-2026-1502 (HTTP injection) and CVE-2026-4786 (command injection) hit Python 3.14 on Fedora. Don't just patch today. Build automation that finds ANY CVE. Read -> tinyurl.com/2krzcetb #Fedora #Security
  • 0
  • 0
  • 0
  • 8h ago
Showing 21 to 24 of 24 CVEs