Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Reported exploitedSecure Firewall Management Center (FMC)SandwormOur summary
Cisco Talos reports active in-the-wild exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC): CVE-2026-20079, a critical authentication bypass (CVSS 10.0) allowing unauthenticated attackers to gain root access, and CVE-2026-20316, which enables low-privileged login that can be chained for privilege escalation.
Analysts have observed three distinct threat clusters leveraging these flaws. One group deployed web shells and a JAR-based command executor, another associated with Sandworm utilized Netcat reverse shells to install Cyclops Blink malware, and a third actor linked to Qilin ransomware used static credentials for reconnaissance and deployment. Cisco advises applying available hotfixes immediately, ahead of a comprehensive hardening release scheduled for the week of September 14.
Below is the opening; the full story is at Cisco Talos.
From Cisco Talos
Wednesday, September 9, 2026 12:08
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.