criticalKEV
CVE-2025-20333
Cisco ASA/FTD VPN web server buffer overflow - unauthenticated root RCE (ArcaneDoor-class; CISA ED 25-03)
- Severity
- critical
- Affected product
- Cisco ASA/FTD WebVPN
- Affected versions
- Cisco ASA/FTD WebVPN all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 90% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Cisco ASA/FTD WebVPN appliance and reports this CVE when the detected version falls inside the affected range below.
Added to CISA KEV the day the advisory published. No version gate: fixes ship as per-train releases the logon page does not disclose.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →