Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
Reported exploitedCisco Secure Firewall Management Center (FMC)SandwormOur summary
Cisco has confirmed that state-sponsored group Sandworm and ransomware operators linked to Qilin are actively targeting two vulnerabilities in Secure Firewall Management Center (FMC). The flaws, identified as CVE-2026-20079 and CVE-2026-20316, allow unauthorized remote attackers to bypass authentication or log in using hard-coded credentials to gain control of the system. While CVE-2026-20316 involves static low-privileged account credentials, CVE-2026-20079 permits root-level command execution via crafted HTTP requests. Talos recommends applying existing hotfixes immediately or restricting internet access to the management interface until the full hardening release is available.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.