ZeroHour
Help Net Securitypublished ()ingested Zeljka Zorz
Part of a story covered by 13 sources: “Sandworm-linked APT and Qilin ransomware affiliates exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316” — merged summary and timeline →

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

criticalExploit / PoC exploited in the wildimportance 88CVE-2026-20079CVE-2026-20316
AI summary · glm-5.3-flash

Cisco Talos confirms nation-state (Sandworm) and ransomware (Qilin) actors actively exploit CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center.

CVE-2026-20079 is a critical unauthenticated authentication bypass in the FMC web interface allowing root-level script and command execution via crafted HTTP requests; CVE-2026-20316 stems from static hard-coded credentials enabling unauthenticated logins. Cisco Talos detailed three intrusion clusters: web shell and JAR deployment for credential theft, a Sandworm-attributed reverse shell and credential-harvesting implant, and a suspected Qilin ransomware operator chain. Cisco urges immediate hotfixes ahead of a comprehensive hardening release the week of September 16, or taking the FMC management interface offline.

  • CVE-2026-20079 authentication bypass allows remote root command execution
  • CVE-2026-20316 static credentials enable unauthenticated FMC access
  • Sandworm linked to reverse-shell implant; Qilin operator linked to ransomware
  • Hotfixes available now; hardening release due week of September 16

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20316
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).

Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29.

5.311% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC)
largeplausibly tens of thousands of FMC deployments worldwide (no published install base)
Full article570 words · extracted from helpnetsecurity.com · click to collapse

State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network.

CVE-2026-20079 CVE-2026-20316 exploited

Two FMC vulnerabilities under active attack

“Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software,” the company’s researchers confirmed on Wednesday.

These are the above mentioned CVE-2026-20079 and CVE-2026-20316, which Cisco flagged as exploited in the wild in July 2026.

Both vulnerabilities are in FMC software’s web interface.

CVE-2026-20079 was discovered by Brandon Sakai of Cisco during internal security testing and fixed / disclosed in early March 2026.

This authentication bypass vulnerability is due to an improper system process that is created at boot time, and allows remote, unauthenticated attackers to execute scripts and commands that allow root access to the device by simply sending specially crafted HTTP requests to an unpatched device.

CVE-2026-20316 was reported by Jimi Sebree of Horizon3.ai and disclosed (with a fix made available) on July 29, when CISA also added it to its Known Exploited Vulnerabilities catalog.

Stemming from static (hard-coded) credentials for a low-privileged account, it allows unauthenticated, remote attackers to log in to an affected device/instance.

Three intrusion clusters, including Sandworm and Qilin activity

When, in July 2026, Cisco confirmed CVE-2026-20316 had been exploited by attackers, it added the same indicators of compromise to the security advisories for both CVE-2026-20316 and CVE-2026-20079, but did not say whether the latter was being leveraged in attacks.

The confirmation came yesterday, when the company’s threat intelligence analysts detailed three intrusion clusters leveraging one or both of these flaws.

The first instrusion cluster exploits CVE-2026-20079 and places a malicious web shell in the CSM Tomcat webroot directory, which is then used to place a malicious JAR file in the same directory. That file allows attackers to execute commands to obtain user authentication data and credentials.

The second intrusion, believed to be the work of Russian state-sponsored group Sandworm, starts with the attackers gaining access via one of the two vulnerabilities. Then they update the license.tmp file with a malicious copy, to establish a reverse shell to their command-and-control server. Finally, they harvest the configuration files of the managed Cisco firewalls, and install an implant that allows them to harvest credentials, execute commands and files, perform packet sniffing and network scanning, and more.

The third one, suspected to be the work of a Qilin ransomware operator, starts with the attackers logging in with the static credentials (CVE-2026-20316), then performing network and endpoint reconnaissance, stealing credentials, establishing additional access, deploying AV killers, and delivering the ransomware.

The analysts shared indicators of compromise related to these threat clusters.

“Due to Talos identifying in the wild abuse of these CVE’s, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316,” they added.

“A comprehensive hardening release consisting of these hotfixes along with other internally discovered vulnerabilities will be released next week (Week of September 16th). Nonetheless, given the in the wild abuse we strongly recommend that customers apply the referenced hotfixes as soon as possible, pending the hardening release.”

An alternative temporary solution is to make the vulnerable FMC management interface inaccessible from the internet.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/10/cisco-fmc-exploited-cve-2026-20079-cve-2026-20316/