The Congressional Budget Office confirmed in November 2025 that it had been hacked. Reporting identifies the primary technical weakness as an unpatched Cisco ASA firewall.
The Product Category, For The Fifth Time This Year
This desk filed at 25-0805 that the 2025 exploitation record is dominated by devices sold as security products — Ivanti, NetScaler, Fortinet, SonicWall — and set out why: internet-facing by design, parsing untrusted input by design, trusted by everything behind them by design.
A firewall appliance at a legislative agency is that argument with the least sympathetic detail attached. Unlike the zero-days at 25-0109 and 25-0624, this is reported as an unpatched device — a known defect with an available fix.
The Corpus Should Not Be Glib About It
The unpatchable argument at 26-0405 holds that vulnerability volume exceeds remediation capacity, and this desk has repeatedly said that patch coverage is a poor metric — at 25-0723, where patched servers still served attackers holding stolen keys.
None of that excuses a perimeter appliance. The corpus made exactly this distinction at 25-0814: a firewall in front of an organisation holding sensitive data is not a long-tail asset competing for attention. It is the front door, and it is a small enough population to track.
What The Agency Holds
A budget office produces cost estimates and economic analysis for legislation before it is public. Its correspondence describes what is being drafted, by whom, and with what fiscal implications.
That is the mail-store argument at 25-1212 and 25-0408 — the value is the reasoning and the relationships, not a record count. Graded medium: this desk has not established what was accessed or by whom, and no actor is named here.
Compiled from public reporting, listed below. The identification of the appliance as the entry point follows that reporting. Scope and attribution are not established. Corrections: corrections@forensicpost.com.