Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Official sources do not establish that Akira ransomware operators used the Cisco ASA zero-days disclosed in 2025. Cisco linked the firewall attacks to the ArcaneDoor campaign; CISA’s separate Akira advisory does not connect Akira to those vulnerabilities. A different, older Cisco flaw has been listed as used in ransomware campaigns, but that listing does not name Akira.

What did Cisco report about the 2025 firewall attacks?

Cisco says it was engaged in May 2025 to investigate attacks against certain ASA 5500-X devices running ASA software with VPN web services enabled. It observed exploitation of multiple zero-day vulnerabilities and efforts to hinder investigation, including disabling logging, intercepting command-line interface (CLI) commands, and crashing devices. Cisco assessed with high confidence that the activity was related to the ArcaneDoor campaign it had reported in early 2024.

Cisco’s September 2025 advisories identified three vulnerabilities in the campaign. Their CVSS base scores describe vulnerability severity; they are not measures of Akira activity, the number of victims, or the campaign’s impact.

Vulnerability Impact stated by Cisco CVSS base score
CVE-2025-20333 Remote code execution 9.9
CVE-2025-20363 Remote code execution 9.0
CVE-2025-20362 Unauthorized access 6.5

The available reporting does not show that these attacks were carried out by Akira. It also does not establish an Akira victim count or ransom total tied to the 2025 Cisco campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does CVE-2025-20333 mean for Cisco firewall operators?

Cisco describes CVE-2025-20333 as improper input validation in HTTP(S) requests to the VPN web server. Exploitation requires a remote attacker to have valid VPN credentials; Cisco says successful exploitation may allow arbitrary code execution with root privileges. The advisory says no workaround addresses the vulnerability and recommends upgrading to a fixed software release.

Cisco’s November 5, 2025 advisory update also says an attack variant against affected, unpatched devices could trigger unexpected reloads and denial of service. That risk is another reason for affected administrators to follow Cisco’s current upgrade guidance rather than relying on a workaround.

Rank #2
Cisco ASA5525-X ASA5525-K9 Security Appliance Firewall (Renewed)
  • Cisco asa 5525-x firewall edition - 8 port - gigabit Ethernet
  • Cisco asa 5525-x firewall edition
  • 8 port - gigabit Ethernet

Why patching may not establish that a device is clean

Cisco’s event response reported that attackers modified ROMMON—the device’s boot firmware—on some compromised ASA 5500-X devices released before Secure Boot and Trust Anchor technologies. Separately, Cisco’s advisory first published April 23, 2026 and updated May 19, 2026 describes a previously unknown ArcaneDoor persistence mechanism in FXOS. On specified platforms, that mechanism may survive an upgrade to fixed releases published in September 2025.

Platforms named in Cisco’s 2026 FXOS advisory

  • Firepower 1000, 2100, 4100, and 9300 series
  • Secure Firewall 1200, 3100, and 4200 series

Cisco gives show kernel process | include lina_cs as a compromise check; according to the advisory, output from the command indicates compromise. Administrators should confirm that the check applies to their platform and follow Cisco’s current instructions before taking action. A software upgrade remains Cisco’s recommendation for the CVE-2025-20333 vulnerability, but an upgrade alone may not rule out persistence on a device affected by the separate FXOS mechanism.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should an organization do if it suspects compromise?

CISA Emergency Directive 25-03 applies to federal agency assets, not all organizations. It directs agencies to identify in-scope devices and follow CISA’s core-dump and hunt process. If compromise is detected, the directive’s response instructions call for disconnecting the device while keeping it powered on, reporting to CISA, and working with CISA on incident response, forensics, and eviction.

The directive’s original deadlines are historical, not upcoming. Federal agencies should check the current directive for applicable scope and requirements. Other organizations should use Cisco’s current platform-specific guidance and involve their incident-response team if compromise is suspected; the federal directive should not be treated as a universal instruction for every environment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does the older CVE-2020-3259 ransomware listing differ?

CISA’s Known Exploited Vulnerabilities catalog identifies CVE-2020-3259 as an information-disclosure flaw affecting specific Cisco ASA and Firepower Threat Defense configurations using AnyConnect and WebVPN. CISA marks it as known to have been used in ransomware campaigns. That is evidence of a broad ransomware association with an older vulnerability, not evidence that Akira exploited it.

This older catalog entry and Cisco’s 2025 ArcaneDoor campaign are separate stories: they involve different vulnerability identifiers and reporting. Neither source, as described here, establishes the claim that Akira used the 2025 Cisco ASA zero-days.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 2
Cisco ASA5525-X ASA5525-K9 Security Appliance Firewall (Renewed)
Cisco ASA5525-X ASA5525-K9 Security Appliance Firewall (Renewed)
Cisco asa 5525-x firewall edition - 8 port - gigabit Ethernet; Cisco asa 5525-x firewall edition
$110.88
Bestseller No. 5
Cisco ASA 5525-X - Security Appliance - with Firepower Services - 8 Ports - GigE (ASA5525-FPWR-K9)
Cisco ASA 5525-X - Security Appliance - with Firepower Services - 8 Ports - GigE (ASA5525-FPWR-K9)
Highly effective intrusion prevention system (IPS) with Cisco global correlation; High-performance VPN and always-on remote access
$395.00
Best Value
Cisco ASA 5525-X - Security Appliance - with Firepower Services - 8 Ports - GigE (ASA5525-FPWR-K9)
  • Broad and deep network security through an array of cloud- and software-based integrated security services
  • Comprehensive antimalware capabilities, including antivirus, botnet traffic filter, and antispyware
  • Highly effective intrusion prevention system (IPS) with Cisco global correlation
  • High-performance VPN and always-on remote access
  • The ability to enable additional security services quickly and easily in response to changing needs

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.