Further to the below mail, another thing that was observed is as follows:
The ACLXX is used for dynamic nat. This includes only some IP's. Any ip that does not match this acl will not get natted. When u inlcude a permit any statement in the acl, all hosts get natted and the cpu came down from 90% to 28% drastically. But this is not intended as some applications dont work well with nat.
So this other traffic which goes without natting is getting process switched or something.