Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io
Cloud Threat Landscape

Cisco ISE Vulnerability Exploited as 0day by APT

Type
Campaign
Actors
❓Unknown
Pub. date
November 13, 2025
Initial access
0-day vulnerability1-day vulnerability
Impact
Data exfiltration
Observed techniques
Credential theftVulnerability exploitationWebshell deployment
Targeted technologies
Cisco ISECitrix NetScaler
References
https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/
Status
Finalized
Last edited
Nov 13, 2025 2:44 PM

Researchers uncovered an advanced persistent threat (APT) exploiting zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems (CitrixBleed2). The vulnerabilities, tracked as CVE-2025-20337 and CVE-2025-5777, were leveraged by the attackers to deploy custom malware. While CVE-2025-5777 has been previously covered, the zero-day exploitation of CVE-2025-20337 represents a new development.

Amazon’s honeypots first detected exploitation of a previously unknown Citrix vulnerability (now CVE-2025-5777, “Citrix Bleed Two”) before public disclosure, indicating active zero-day exploitation. During related activity, Amazon identified a separate exploit targeting Cisco ISE through an undocumented endpoint. This vulnerability, later designated CVE-2025-20337, involved insecure deserialization logic that allowed pre-authentication remote code execution and full administrative compromise.

Post-exploitation, attackers deployed a custom in-memory web shell disguised as a legitimate Cisco ISE component named IdentityAuditAction. The shell utilized Java reflection and Tomcat listeners to intercept HTTP requests, encrypting communications using DES with non-standard Base64 encoding. No IOCs have been published for this activity.

Made with 💙 by Wiz

Last Updated: April 3, 2025