ZeroHour
Cisco Talospublished ()ingested

Cisco Talos Antivirus

highRansomware exploited in the wildimportance 60CVE-2026-20182CVE-2025-20333CVE-2025-20362

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20333
+1 in the same advisory: …20362
Authenticated Buffer Overflow RCE in Cisco ASA/FTD VPN Web Server

CVE-2025-20333 is a buffer overflow (CWE-120) in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, caused by improper validation of user-supplied input in HTTP(S) requests. An attacker who already holds valid VPN user credentials can trigger it by sending crafted HTTP(S) requests to the device's VPN web interface; the flaw is remotely exploitable over the network with low attack complexity and no user interaction. A successful exploit allows arbitrary code execution as root, possibly resulting in complete compromise of the firewall or VPN gateway. Any organization running Cisco ASA or FTD software with the VPN web server enabled is affected. Exploitation is confirmed in the wild: the CVE was added to CISA's KEV on 2025-09-25, EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), and Cisco and the UK NCSC have warned of real-world attacks (including RayInitiator and LINE VIPER malware deployment) that chain this flaw with at least one companion Cisco vulnerability.

Do: Inventory all ASA/FTD devices with the VPN web server reachable by users (especially internet-exposed ones) and upgrade to the fixed releases listed in the Cisco PSIRT advisory; where patching is delayed, apply Cisco's recommended mitigations and hunt for indicators of the reported attack chain (RayInitiator/LINE VIPER). Because exploitation requires valid VPN credentials, treat VPN user credentials on affected gateways as potentially compromised and force resets. US federal agencies must follow the mitigation steps in CISA Emergency Directive 25-03 and BOD 22-01 timelines for this KEV entry.

9.9
group max
71% KEV
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass≈100,000–300,000 internet-exposed ASA/FTD VPN web servers (order of magnitude), within a multi-million-device installed base serving large VPN user populations
CVE-2026-20182
Authentication Bypass in Cisco Catalyst SD-WAN Control Components

CVE-2026-20182 is a critical authentication flaw (CWE-287) in the control-connection peering authentication of Cisco Catalyst SD-WAN Controller (formerly vSmart), Manager (formerly vManage), and Validator (formerly vBond). Because the peering authentication mechanism does not work properly, an unauthenticated, remote attacker can send crafted requests during the control-connection handshake and log in to the controller as an internal, high-privileged, non-root user without valid credentials. With this access, the attacker can reach NETCONF and manipulate network configuration across the entire SD-WAN fabric. Any organization running these Catalyst SD-WAN control components is affected, and the flaw carries a CVSS 3.1 score of 10.0 and a 91.5% EPSS score. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-14, confirming exploitation in the wild, amid a series of exploited Cisco SD-WAN zero-days including a compromise at a communications service provider.

Do: Upgrade affected Catalyst SD-WAN Controller, Manager, and Validator components to the fixed releases identified in Cisco's May 2026 advisory (version numbers are not provided in this data). Use the advisory's 'show control connections' guidance to inspect control-connection handshaking for anomalies and audit for unauthorized high-privileged non-root accounts and unexpected NETCONF sessions. Operators — especially federal agencies — should follow CISA Emergency Directive 26-03 and CISA's Hunt & Hardening Guidance for Cisco SD-WAN Devices, including restricting internet exposure of SD-WAN management interfaces until patched.

10.092% KEV
  • Cisco Catalyst SD-WAN Controller (formerly SD-WAN vSmart)
  • Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage)
  • Cisco Catalyst SD-WAN Validator / vBond Orchestrator (formerly SD-WAN vBond)
largeon the order of tens of thousands of affected control-plane systems (controllers, managers, validators) across enterprise, service-provider, and government…
Full article312 words · extracted from blog.talosintelligence.com · click to collapse

Cisco Talos Antivirus, also known as ClamAV, delivers foundational malware protection through deep file analysis and industry-leading signature detection. As an open-source solution embedded across Cisco’s security, networking, and collaboration products, Talos Antivirus provides robust protection against known malware threats, making it a trusted choice for enterprises, service providers, and individuals worldwide.

August 13, 2026 06:00

Dissecting the JWR phishing framework

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.

May 14, 2026 12:02

Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.

May 5, 2026 06:00

UAT-8302 and its box full of malware

Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.

April 23, 2026 11:10

UAT-4356's Targeting of Cisco Firepower Devices

Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices.

April 16, 2026 06:00

PowMix botnet targets Czech workforce

Cisco Talos discovered an ongoing malicious campaign, operating since at least December 2025, affecting a broader workforce in the Czech Republic with a previously undocumented botnet we call “PowMix.”

April 3, 2026 13:00

Axios NPM supply chain incident

Overview of the recent Axios NPM supply chain incident including details of the payloads delivered from actor-controlled infrastructure.

April 2, 2026 06:00

Qilin EDR killer infection chain

This blog provides an in-depth analysis of the malicious “msimg32.dll” used in Qilin ransomware attacks, which is a multi-stage infection chain targeting EDR systems.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/category/cisco-talos-antivirus/