ZeroHour

Search: “Secure Firewall Management Center”

4 stories in the last 3d

ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-20242, an unauthenticated deserialization flaw in Cisco Secure Firewall Management Center enabling remote code execution (CVSS 8.1).

ZDI published advisory ZDI-26-709 describing deserialization of untrusted data in Cisco Secure Firewall Management Center's CommandSinkRmi component, tracked as CVE-2026-20242 with CVSS 8.1. Remote attackers can execute arbitrary code on affected installations without authentication. The advisory does not indicate whether exploitation has been observed in the wild.

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

Cisco's September 2026 firewall hardening release fixes internally found ASA, FTD, and FMC flaws, two of which are actively exploited.

Cisco released September 2026 hardening updates for Secure Firewall ASA, FTD, and FMC software addressing multiple vulnerabilities discovered during a comprehensive internal security review. Two of the vulnerabilities are known to be actively exploited, including a Cisco Secure Firewall Management Center static credential vulnerability. Details are provided in separate linked advisories.

Cisco Security Advisories · 14h agoAdvisory in the wild 6 sources

Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities

Sophos uncovers a 64-bit Cyclops Blink variant on hacked Cisco FMC appliances, adding internal network scanning and selective packet capture; linked to Sandworm.

Sophos CTU analyzed a new 64-bit x86-64 Cyclops Blink implant (timezone_check) deployed on Cisco Secure Firewall Management Center appliances compromised via CVE-2026-20079 authentication bypass and CVE-2026-20316 low-privileged login. The activity is assessed with high confidence as Russian-nexus, with a moderate-confidence link to Sandworm (IRON VIKING, also tracked as Seashell Blizzard). The implant runs a parent controller plus five worker modules, masquerades as [kworker/0:1], persists via SysV init scripts at /lib/tz/timezone_check, and beacons to hard-coded C2 89.34.96.56 over a custom TLS protocol on ports 43856 and 49172. New module 0x11 scans internal IPv4 networks for SSH, SMB, LDAP, VMware, HTTP/HTTPS and VPN services, while module 0x12 performs filtered packet capture that can expose cleartext credentials, cookies and tokens.

GBHackers · 2d agoMalware in the wild 9 sourcesCVE-2026-20079CVE-2026-20316

Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning

Sophos uncovers a new x86-64 Cyclops Blink Linux implant with packet sniffing and internal network scanning on compromised Cisco FMC appliances.

Sophos identified a 64-bit Linux Cyclops Blink implant in August on compromised Cisco Firewall Management Center devices, persisting via SysV init scripts and masquerading as the process 'kworker01'. The modular malware runs five child processes for reconnaissance, file transfer, scanning, packet capture, and persistence, and beacons hourly over outbound TLS to hardcoded C2 89.34.96.56 on ports 43856 and 49172. The family was previously tied to Russian-linked Sandworm activity on WatchGuard appliances, though Sophos treats 2026 attribution cautiously. The packet-capture module applies configurable filters to retain credentials, cookies, and authentication tokens from raw Ethernet traffic.

Cyber Security News · 2d agoMalware in the wild