CVE Tools

Organizations Warned of Cisco Secure FMC Exploitation

SecurityWeekBy Eduard Kovacs

Reported exploitedCisco Secure Firewall Management Center (FMC)Sandworm

Our summary

Cisco and CISA have confirmed active in-the-wild exploitation of CVE-2026-20079, a critical authentication bypass flaw in Cisco Secure Firewall Management Center (FMC). This vulnerability permits remote attackers to execute arbitrary scripts and gain root access by sending crafted HTTP requests to vulnerable systems. Talos has linked the attacks to Russian APT group Sandworm, which deployed Cyclops Blink malware, and the Qilin ransomware syndicate, which used the breach for reconnaissance and credential theft. Organizations should apply the patch released in early March and restrict internet-facing exposure of the FMC interface.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store