CVE Tools

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco TalosBy Cisco Talos8 min read

Reported exploitedSecure Firewall Management Center (FMC)Sandworm

Our summary

Cisco Talos reports active in-the-wild exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC): CVE-2026-20079, a critical authentication bypass (CVSS 10.0) allowing unauthenticated attackers to gain root access, and CVE-2026-20316, which enables low-privileged login that can be chained for privilege escalation.

Analysts have observed three distinct threat clusters leveraging these flaws. One group deployed web shells and a JAR-based command executor, another associated with Sandworm utilized Netcat reverse shells to install Cyclops Blink malware, and a third actor linked to Qilin ransomware used static credentials for reconnaissance and deployment. Cisco advises applying available hotfixes immediately, ahead of a comprehensive hardening release scheduled for the week of September 14.

Read at Cisco Talos

Below is the opening; the full story is at Cisco Talos.

From Cisco Talos

Wednesday, September 9, 2026 12:08

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.…

Continue at Cisco Talos

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store