NVD disclosure day

Published threat advisories for September 25, 2025

CVE advisoryCRITICAL

CVE-2025-20363

Cisco ASA FTD IOS IOS XE IOS XR HTTP Request Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical vulnerability exists in Cisco network devices that could allow an attacker to execute arbitrary code, leading to a full device compromise. This is due to improper handling of user-supplied input in HTTP requests. The potential for compromise of critical network infrastructure warrants attention to confirm re

CVE advisoryKnown Exploit

CVE-2025-20362

Cisco Firewall VPN Web Server Unauthorized Access Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Cisco Secure Firewall VPN web servers allows unauthenticated attackers to access restricted URLs. This could lead to unauthorized access, impacting system availability and data confidentiality for affected organizations. Organizations should address this risk promptly.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-20333

Cisco Secure Firewall VPN Vulnerability Allows Code Execution.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Cisco Secure Firewall VPN web servers could allow an authenticated attacker to execute arbitrary code. This could lead to complete compromise of affected devices. The U.S. CISA has identified this as a known exploited vulnerability.

• CISA KEV