CVE Tools

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

Help Net SecurityBy Zeljka Zorz

Reported exploitedCisco Secure Firewall Management Center (FMC)Sandworm

Our summary

Cisco has confirmed that state-sponsored group Sandworm and ransomware operators linked to Qilin are actively targeting two vulnerabilities in Secure Firewall Management Center (FMC). The flaws, identified as CVE-2026-20079 and CVE-2026-20316, allow unauthorized remote attackers to bypass authentication or log in using hard-coded credentials to gain control of the system. While CVE-2026-20316 involves static low-privileged account credentials, CVE-2026-20079 permits root-level command execution via crafted HTTP requests. Talos recommends applying existing hotfixes immediately or restricting internet access to the management interface until the full hardening release is available.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store