iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
ArcaneDoor is Cisco’s name for an espionage-focused attack campaign against devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. It began with attacks disclosed in 2024, expanded through related activity reported in 2025, and now includes an FXOS persistence technique that Cisco says can survive upgrades to the fixed releases issued in September 2025. Updating is necessary, but Cisco’s current detection and response checks are also required to determine whether a device is compromised.
What ArcaneDoor means
Cisco’s Product Security Incident Response Team identified attacks against certain ASA and FTD software installations in early 2024 and named the campaign ArcaneDoor. In its initial event response, Cisco said it had not identified how the attackers first gained access. Cisco Event Response: Attacks Against Cisco Firewall Platforms
The first public response, dated April 24, 2024, linked three vulnerabilities to the campaign. Cisco explicitly said the attacker used CVE-2024-20353 and CVE-2024-20359; CVE-2024-20358 was associated with the campaign but was not identified as used in that statement.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →How the incident evolved
| Period | What Cisco reported | Scope and capability | Administrator implication |
|---|---|---|---|
| Early 2024 | Attacks against certain devices running ASA or FTD software; initial entry method not identified. | Three 2024 vulnerabilities were associated with ArcaneDoor; two were specifically reported as exploited. | Apply Cisco’s fixed releases and use the original event-response guidance. |
| May–September 2025 | Cisco assisted government incident-response organizations investigating attacks on ASA 5500-X devices with VPN web services enabled. Cisco assessed with high confidence that the activity was related to the 2024 ArcaneDoor actor. | The later activity used multiple zero-days. Cisco’s September 25, 2025 response covered CVE-2025-20333, CVE-2025-20363 and CVE-2025-20362. | Use the continued-attacks response, not only the 2024 advisory. |
| November 5, 2025 | Cisco described a new attack variant against affected releases. | Unpatched devices could reload, creating denial-of-service conditions. | Check whether devices remain on affected releases and follow Cisco’s updated exposure guidance. |
| April–May 2026 | Cisco disclosed a previously unknown persistence mechanism in FXOS and broadened the described activity from ASA 5500-X to devices running ASA or FTD software. | The mechanism can remain after upgrading to fixed releases published in September 2025. Cisco says devices that support Secure Boot are not affected by this persistence capability. | An upgrade does not by itself establish that a device is clean; run the current, model-specific detection and response checks. |
Sources: Cisco’s 2024 event response, Cisco’s continued-attacks response (Version 2.3, updated April 24, 2026), and Cisco’s FXOS persistence advisory (updated May 19, 2026).
#1 Best Overall
- Cisco asa 5525-x firewall edition - 8 port - gigabit Ethernet
- Cisco asa 5525-x firewall edition
- 8 port - gigabit Ethernet
The ArcaneDoor CVEs Cisco identified
CVSS base scores indicate the technical severity Cisco assigned to each weakness. They are not counts of victims, estimates of compromise, or measures of how widespread exploitation was.
| CVE | Cisco’s description or campaign role | CVSS base score | Timeframe |
|---|---|---|---|
| CVE-2024-20353 | Web services denial of service; Cisco said it was used by the attacker. | 8.6 | 2024 campaign |
| CVE-2024-20358 | Command injection; associated with the 2024 campaign. | 6.0 | 2024 campaign |
| CVE-2024-20359 | Persistent local code execution; Cisco said it was used by the attacker. | 6.0 | 2024 campaign |
| CVE-2025-20333 | Covered in Cisco’s response to the later attacks. | 9.9 | 2025 activity |
| CVE-2025-20363 | Covered in Cisco’s response to the later attacks. | 9.0 | 2025 activity |
| CVE-2025-20362 | Covered in Cisco’s response to the later attacks. | 6.5 | 2025 activity |
The 2024 CVEs and the 2025 CVEs should not be treated as one original six-item disclosure. They belong to different Cisco responses as the campaign developed. The scores and exploitation statements come from Cisco’s 2024 event response and Cisco’s continued-attacks response.
Rank #2
- More for the money with this high quality Product
- Offers premium quality at outstanding saving
- Excellent product
- 100% satisfaction
Which devices and software are in scope?
Original 2024 wording
Cisco initially described the target set as certain devices running ASA or FTD software. That formulation did not identify every model or every software release as compromised.
Later 2025 observations
The May 2025 investigations involved ASA 5500-X Series devices running ASA software with VPN web services enabled. This was the observed focus of that investigation, not a statement that other ASA or FTD deployments were safe.
Rank #3
- Asa 5506-X With Firepower Services, 8Ge Data, 1Ge Mgmt., Ac, 3Des/Aes
- Design That Delivers High Availability, Scalability, And For Maximum Flexibility And Price/Performance
- Made In Mexico
- Number Of Ports: 8
April 2026 expansion
Cisco’s April 2026 update states that the activity’s scope broadened to devices running ASA or FTD software and describes the newly discovered persistence as an FXOS capability on affected hardware platforms. Cisco says the persistence does not affect devices that support Secure Boot. Check your exact hardware, software train and security features against Cisco’s current advisories rather than inferring coverage from the product family name alone.
Why installing a fixed release is not the complete answer
Cisco’s earlier guidance strongly recommended upgrading to fixed software versions. Its April 2026 reporting adds a material qualification: the FXOS persistence mechanism can be preserved through an upgrade to the fixed releases published in September 2025. A successful upgrade therefore addresses vulnerable software exposure but does not, on its own, prove that an already-compromised device has been cleared.
Rank #4
- This Certified Refurbished product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box.
- Available PoE Power - 0 if None (W): 240
- Forwarding Performance (Mpps): 0
- Switching Capacity (Gbps): 0
- Total WAN 10/100/1000 Ports: 8
The practical distinction is between remediation and verification. Remediation means moving to the fixed release Cisco specifies for your platform. Verification means applying the current detection guide’s checks, reviewing the results in the context of the device model and release, and following Cisco’s response instructions when an indicator is present or the result is inconclusive.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What administrators should do now
- Inventory the affected surface. Record every appliance running ASA or FTD software, its hardware platform, software release, enabled VPN web services and whether Secure Boot is supported. Include devices that were upgraded after September 2025.
- Use Cisco’s live event-response page for release guidance. Start with Cisco Event Response: Continued Attacks Against Cisco Firewalls, which incorporates the later 2025 and 2026 updates. Follow the fixed-release instructions that match each platform and software train.
- Run the complete, applicable detection procedure. Cisco’s Detection Guide for Continued Attacks against Cisco Firewalls by the Threat Actor behind ArcaneDoor is version 1.2 dated April 24, 2026. Its commands and indicators vary by model and release; do not substitute a check from another platform.
- Preserve and escalate evidence when a check matches. Treat a positive or unexplained result as a security incident, preserve relevant device and network evidence, and use Cisco’s response instructions and support channels for the affected platform. Do not assume that reinstalling or upgrading alone removes persistence.
- Recheck after remediation. Once the device is on the prescribed fixed release, repeat the detection steps that apply to that model and document the result. Keep the evidence and software version together so a later investigation can distinguish the pre-upgrade state from the verified state.
A concrete detection-guide example
Cisco gives a model- and release-specific example for administrators who upgraded an ASA 5512-X, 5515-X, 5525-X, 5545-X or 5555-X device to ASA Software 9.12.4.72 or 9.14.4.28: look for firmware_update.log on disk0:. This is one indicator for that exact model and release context, not a universal ArcaneDoor test. Use the complete guide for the command syntax, additional models, other releases and interpretation of results.
Quick Recap
Best Value
Key takeaways
- ArcaneDoor is an evolving campaign name, not a single 2024 patch event.
- The 2024 campaign involved CVE-2024-20353 and CVE-2024-20359 according to Cisco’s exploitation statement; CVE-2024-20358 was also associated with that campaign.
- Cisco later reported related 2025 activity and three additional CVEs in a separate response.
- The April 2026 FXOS disclosure means persistence may survive upgrades to September 2025 fixed releases, except on devices Cisco says support Secure Boot.
- Use fixed software plus Cisco’s current, device-specific detection and response guidance to establish the device’s status.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

