Cisco FMC CVE-2026-20079 (CVSS 10.0) actively exploited: Sandworm-linked Cyclops Blink and Qilin ransomware target Secure Firewall Management Center
Cisco confirmed active exploitation of CVE-2026-20079 (CVSS 10.0, unauthenticated authentication bypass enabling root code execution) and CVE-2026-20316 (CVSS 5.3, hard-coded static credentials) in Secure Firewall Management Center. Cisco Talos tracks three…
Cisco confirmed in-the-wild exploitation of CVE-2026-20079, a maximum-severity (CVSS 10.0) unauthenticated authentication bypass in Cisco Secure Firewall Management Center (FMC) that lets attackers hijack an unclaimed boot session and execute scripts as root, alongside CVE-2026-20316 (CVSS 5.3), a hard-coded static-credential flaw permitting low-privileged login that can be chained for privilege escalation and sensitive data access. Cisco Talos identified three post-compromise activity clusters: UAT-12197, which deployed a home.jsp JSP web shell and a cmd.jar command executor, harvesting credentials from internal databases via OmniQuery.pl; UAT-11823, assessed as Sandworm-linked, which chained both flaws and deployed a Netcat reverse shell plus a Cyclops Blink variant with DoH C2 and init.d persistence; and UAT-11988, a Qilin ransomware affiliate that used static credentials for reconnaissance — Active Directory enumeration, living-off-the-land FMC tooling, SOCKS5 proxies, reverse-SSH tunnels, impacket, Invoke-TheHash, and custom AV killers — before deploying Qilin ransomware. Cisco released hotfixes and urged immediate installation, with a broader hardening release planned for the week of September 14, 2026. CISA added the flaws to the KEV catalog with a September 12, 2026 remediation deadline for US federal agencies; sources agree on the deadline but differ on whether it covers both CVEs or specifically CVE-2026-20079 (CVE-2026-20316 was reportedly added to KEV in late July 2026). In a September 14 follow-up, Sophos CTU analyzed a new 64-bit x86-64 Cyclops Blink implant ('timezone_check') deployed on compromised FMC appliances, assessed with high confidence as Russian-nexus and with moderate confidence linked to Sandworm (IRON VIKING, also tracked as Seashell Blizzard). The implant runs a parent controller plus five worker modules, masquerades as [kworker/0:1], persists via SysV init scripts at /lib/tz/timezone_check, adds iptables rules, and beacons to hard-coded C2 89.34.96.56 over a custom TLS protocol on ports 43856 and 49172. New module 0x11 scans internal IPv4 networks for SSH, SMB, LDAP, VMware, HTTP/HTTPS and VPN services, while module 0x12 performs filtered packet capture that can expose cleartext credentials, cookies, and tokens. Because FMC centrally manages Cisco Secure Firewall deployments, enterprise exposure is likely.
- CVE-2026-20079 (CVSS 10.0): unauthenticated web-interface authentication bypass in Cisco Secure Firewall Management Center allowing root-level script/code execution via hijacking an unclaimed boot session.
- CVE-2026-20316 (CVSS 5.3): hard-coded static credentials permitting low-privileged remote login; exposes sensitive data and can be chained for privilege escalation.
- Cisco Talos identified three post-compromise clusters: UAT-12197, UAT-11823, and UAT-11988.
- UAT-12197 deployed a home.jsp web shell and cmd.jar command executor, extracting credentials from internal databases via OmniQuery.pl.
- UAT-11823, tied to Sandworm's tooling, used a Netcat reverse shell and deployed a Cyclops Blink variant with init.d persistence, DoH C2, configuration harvesting, and credential theft.
- UAT-11988, a Qilin ransomware affiliate, used static credentials for reconnaissance (AD enumeration, living-off-the-land FMC tooling, SOCKS5 proxies, reverse-SSH tunnels, impacket, Invoke-TheHash, custom AV killers) before deploying Qilin…
- Cisco hotfixes are available now, with a broader hardening release planned for the week of September 14, 2026.
- CISA added the flaws to the KEV catalog with a September 12, 2026 remediation deadline for US federal (FCEB) agencies; one report ties the deadline to both CVEs, while others tie it specifically to CVE-2026-20079 and say CVE-2026-20316 was…
Coverage timelineoldest first · each row is one article
- · 7d agoCisco FMC CVE-2026-20079 Actively Exploited
SOCRadar· 85
Cisco confirms active exploitation of CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-20316 | Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile). Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29. | 5.3 | 11% | KEV ransomware |
| largeplausibly tens of thousands of FMC deployments worldwide (no published install base) |