ZeroHour

Search: “cve-2026-20316”

16 stories

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

Cisco Talos confirms nation-state (Sandworm) and ransomware (Qilin) actors actively exploit CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center.

CVE-2026-20079 is a critical unauthenticated authentication bypass in the FMC web interface allowing root-level script and command execution via crafted HTTP requests; CVE-2026-20316 stems from static hard-coded credentials enabling unauthenticated logins. Cisco Talos detailed three intrusion clusters: web shell and JAR deployment for credential theft, a Sandworm-attributed reverse shell and credential-harvesting implant, and a suspected Qilin ransomware operator chain. Cisco urges immediate hotfixes ahead of a comprehensive hardening release the week of September 16, or taking the FMC management interface offline.

Help Net Security · 7d agoExploit / PoC in the wildCVE-2026-20079CVE-2026-20316

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos reports in-the-wild exploitation of critical FMC flaw CVE-2026-20079 by three clusters including a Sandworm-linked APT and Qilin ransomware affiliates.

Cisco Talos is tracking active exploitation of CVE-2026-20079 (CVSS 10.0), an authentication bypass in Cisco Secure Firewall Management Center that lets unauthenticated remote attackers execute scripts and obtain root access, and CVE-2026-20316 (CVSS 5.3), which permits low-privileged logins and can be chained for privilege escalation. Talos identified three post-compromise clusters: UAT-12197 deploying JSP web shells and a JAR command executor for credential theft; UAT-11823, an APT overlapping with Sandworm, deploying a Netcat reverse shell and Cyclops Blink malware; and UAT-11988, assessed as a ransomware operator with TTPs consistent with Qilin affiliates. Hotfixes are available, with a comprehensive hardening release due the week of September 14, 2026.

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three threat groups, including Qilin ransomware operators, exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 for root access, credential theft, and ransomware.

Cisco Talos identified three post-compromise clusters exploiting recently patched Cisco Secure Firewall Management Center flaws. UAT-12197 deploys JSP web shells and harvests credentials; UAT-11823 (with Sandworm-overlapping tooling) installs Cyclops Blink for persistence; UAT-11988 (Qilin) uses static credentials, extensive reconnaissance, SOCKS5 proxies, reverse-SSH tunnels, AV killers, and ransomware deployment. CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 patch deadline for federal agencies; Cisco urges immediate hotfix application.

Security Affairsupdated · 4h agofirst · 6d agoExploit / PoC in the wild 8 sourcesCVE-2026-20079CVE-2026-203165· 2 reads

Organizations Warned of Cisco Secure FMC Exploitation

Cisco and CISA warn that critical FMC authentication bypass CVE-2026-20079 is actively exploited; CISA added it to the KEV catalog with a September 12 deadline.

Cisco and CISA flagged active exploitation of CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center allowing remote, unauthenticated attackers to run malicious scripts and gain root access via crafted HTTP requests. Cisco patched the flaw in early March and added IoCs in late July, but confirmed active exploitation in its September 9 advisory; CISA added it to the KEV catalog requiring federal remediation by September 12. Talos identified three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored and financially motivated actors, and this is the third FMC vulnerability in KEV this year after CVE-2026-20316 and CVE-2026-20131.

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass enabling unauthenticated root command execution in Secure FMC; CISA added it to KEV.

Cisco confirmed in August 2026 that CVE-2026-20079 (CVSS 10.0), an unauthenticated authentication bypass in Secure Firewall Management Center, is being actively exploited, allowing remote attackers to execute scripts and commands as root via crafted HTTP requests to the web interface. CISA added the flaw to its Known Exploited Vulnerabilities catalog, ordering federal civilian agencies to patch by September 12, 2026. Shared IOCs, identical hot fixes, and a July 23 log entry suggest CVE-2026-20079 was used alongside the separately exploited static-credential flaw CVE-2026-20316 in the same attacks. Cisco released patches and cloud fixes, warns hot fixes do not remediate already-compromised devices, and says there are no workarounds.

BleepingComputer · 7d agoExploit / PoC in the wildCVE-2026-20079CVE-2026-20316

ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability

ZDI discloses CVE-2026-20316, a 9.8-rated unauthenticated authentication bypass in Cisco Secure Firewall Management Center login.cgi.

ZDI-26-533 describes an authentication bypass vulnerability in Cisco Secure Firewall Management Center's login.cgi that allows remote attackers to bypass authentication without any credentials. ZDI assigned a CVSS score of 9.8, and the flaw is tracked as CVE-2026-20316. As a central management plane for firewall infrastructure, compromise could enable broad policy changes.

ZDI Published Advisories · Aug 11, 2026VulnerabilityCVE-2026-20316

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco patches dozens of critical flaws in FMC, ISE and Nexus Dashboard, including ISE bugs and an authentication bypass already exploited in the wild.

Cisco released patches for dozens of critical-severity CVEs in Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard. ISE updates cover 20 CVEs including 12 critical ones; three publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) enable SQL injection, data tampering and command execution but require administrative access. FMC patches fix 18 CVEs, eight critical, several shared with ASA and FTD, where CVE-2026-20079 and CVE-2026-20316 have been exploited since August. Cisco also warned of a critical-severity ISE authentication bypass exploited in the wild as a zero-day.

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Cisco warns CVE-2026-76461 (CVSS 9.8), an unauthenticated root RCE in Secure Email Gateway AsyncOS, is actively exploited in the wild.

Cisco confirmed that CVE-2026-76461, a CVSS 9.8 email-parsing flaw in Secure Email Gateway AsyncOS, is being exploited in the wild since September 2026, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted emails containing malicious SQL statements. All physical and virtual SEG configurations are affected; Secure Email and Web Manager and Secure Web Appliance are not. CISA added the flaw to the KEV catalog with a September 17 federal remediation deadline, and Cisco released IoCs while noting root access lets attackers remove them.

SecurityWeekupdated · 23h agofirst · 2d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461CVE-2025-20393CVE-2026-20079+1 CVEs2

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Weekly roundup: Cisco FMC and N-able N-central zero-days exploited in the wild, MikroTik RouterOS hijacks, Microsoft Patch Tuesday ships two exploited zero-days.

State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center (FMC), alongside CVE-2026-20316. N-able issued an emergency hotfix for CVE-2026-86218, a critical pre-auth RCE in the N-central RMM platform exploited in the wild. CERT Polska disclosed six RouterOS vulnerabilities being chained to hijack internet-exposed MikroTik devices. Microsoft's September 2026 Patch Tuesday shipped a record patch count including two zero-days, while roughly 67,000 Trezor customers faced phishing after a shipping-partner breach and researchers privately disclosed a zero-click WeChat worm to Tencent.

Help Net Security · 4d agoExploit / PoC in the wildCVE-2026-20079CVE-2026-20316CVE-2026-862182· 1 read

We've got one word for it, and it's usually the wrong one

Cisco Talos's Threat Source newsletter critiques 'burnout' terminology, describing four occupational injuries, and flags a UAT-10820 WebDAV stealer campaign at a Ukrainian government organization.

Cisco Talos's Threat Source newsletter argues that 'burnout' is the wrong word for most cybersecurity occupational harm, distinguishing exhaustion, secondary traumatic stress, vicarious trauma, and moral injury based on clinical literature from trauma-exposed professions. The featured disclosure describes a complex WebDAV infection chain found at a Ukrainian government organization, attributed with moderate confidence to the Russian-tracked actor UAT-10820 and assessed as an opportunistic cryptocurrency and credential-stealing operation. The campaign delivers the Amatera stealer alongside ZigCryptoStealer and NetSupport Manager, abusing BNB Smart Chain bulletproof hosting, fake CAPTCHA prompts, a vulnerable driver to kill EDR, and rundll32.exe execution of disguised DLLs with ordinal calls. Weekly headlines also cover a Microsoft Defender 'ShieldCrash' zero-day exploit released after September 2026 Patch Tuesday, a North Korean Linux espionage toolkit backdooring HAProxy, and a multi-hop Google-domain redirect phishing campaign.

Cisco Talos · 6d agoIndustry in the wild1