CVE-2025-20333: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. Customers are strongly advised to apply available hotfixes immediately.
Indicators of Compromise
- ip: 208.123.119.215
- cve: CVE-2025-20333
- cve: CVE-2025-20362
- cve: CVE-2026-20079
- cve: CVE-2026-20182
- cve: CVE-2026-20316
- hash: 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461
- hash: b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d
- hash: db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e
- ip: 91.214.78.118
CVE-2025-20333: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Cisco Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
Description
Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. Customers are strongly advised to apply available hotfixes immediately.
CVSS v3.1
Score 9.9critical
Affected software
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- cisco
- Date Reserved
- 2024-10-10T19:15:13.255Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip208.123.119.215 | — | |
ip91.214.78.118 | — |
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2025-20333 | — | |
cveCVE-2025-20362 | — | |
cveCVE-2026-20079 | — | |
cveCVE-2026-20182 | — | |
cveCVE-2026-20316 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | — | |
hashb037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d | — | |
hashdb491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | — |
Threat ID: 68d56a80611617954beac28c
Added to database: 09/25/2025, 16:14:56 UTC
Last enriched: 05/16/2026, 08:51:38 UTC
Last updated: 09/10/2026, 16:40:58 UTC
Views: 312
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.