CVE Tools

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

Dark ReadingBy Jai Vijayan

Reported exploitedSecure Firewall Management CenterSandworm

Our summary

Researchers confirm that Sandworm-linked actors are actively exploiting two vulnerabilities in Cisco Secure Firewall Management Center (FMC) to deploy an updated version of the Cyclops Blink malware implant. By chaining a maximum severity authentication bypass flaw (CVE-2026-20079) with a secondary privilege escalation bug (CVE-2026-20316), the threat actor establishes a reverse shell before installing the 64-bit Linux-capable malware.

This newer variant expands traditional capabilities to include active network scanning and live traffic capture, posing a significant risk to organizations relying on these appliances for network management. Cisco has released emergency hotfixes for both CVEs and urges immediate application due to confirmed in-the-wild exploitation, with a broader hardening release expected shortly.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store