ZeroHour
Story · 1 source · 1 articlefirst updated ()

Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 actively exploited by Sandworm-linked APT and Qilin ransomware affiliates

What's new: Since the previous summary (September 10, ~11:36 UTC), reports from SOCRadar, Cyber Security News, and BleepingComputer (September 10) plus GBHackers, The Hacker News, and Security Affairs (September 11) added granular TTP and attribution detail. UAT-11823 is now reported by GBHackers as attributed with high confidence to a Sandworm-linked APT, with BleepingComputer specifying that its Cyclops…
Merged summary · glm-5.3 · rewritten as coverage arrives

Cisco Talos confirms in-the-wild exploitation of critical FMC authentication bypass CVE-2026-20079 (CVSS 10.0) and chained static-credential flaw CVE-2026-20316 (CVSS 5.3) by three clusters — including a Sandworm-overlapping APT deploying Cyclops Blink and…

Cisco Talos is tracking active, in-the-wild exploitation of two flaws in Cisco Secure Firewall Management Center (FMC), which centrally manages Cisco Secure Firewall deployments. CVE-2026-20079 (CVSS 10.0) is an unauthenticated authentication bypass in the FMC web interface stemming from an improper system process created at boot time; it lets a remote, unauthenticated attacker hijack an unclaimed boot session, execute scripts and commands, and obtain root access via crafted HTTP requests, with the attack surface limited when the management interface is not internet-facing. CVE-2026-20316 (CVSS 5.3) stems from static hard-coded credentials permitting low-privileged unauthenticated logins and can be chained for privilege escalation. Shared IOCs, identical hot fixes, and a July 23, 2026 log entry suggest both flaws were used in the same attacks. CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog on September 9, 2026, requiring federal (FCEB) agencies to remediate by September 12, 2026; CVE-2026-20316 was KEV-listed in late July 2026, and per SecurityWeek this is the third FMC vulnerability in KEV this year after CVE-2026-20316 and CVE-2026-20131, both exploited as zero-days earlier in 2026. Talos identified three post-compromise clusters: UAT-12197 dropped a home.jsp JSP web shell and cmd.jar command executor to query internal databases and steal credentials via OmniQuery.pl; UAT-11823, an APT whose tooling overlaps Sandworm (GBHackers reports high-confidence attribution to a Sandworm-linked APT), deployed a Netcat reverse shell and a Cyclops Blink variant — delivered via a malicious license.tmp file with init.d persistence and DoH C2 — previously attributed to Russia's Sandworm; and UAT-11988, a Qilin ransomware affiliate that abused the static-credential flaw, performed Active Directory enumeration and credential harvesting using living-off-the-land FMC tooling, impacket, Invoke-TheHash, SOCKS5 proxies, reverse-SSH tunnels, and custom AV killers, then staged reconnaissance data and deployed Qilin ransomware on selected endpoints. Cisco released patches and cloud fixes and urges immediate hotfix installation, warning that hot fixes do not remediate already-compromised devices and that no workarounds exist; defenses include applying patches and keeping the FMC management interface off the internet. A comprehensive hardening release is due the week of September 14, 2026 (Talos, GBHackers), though Help Net Security states the week of…

  • CVE-2026-20079 (CVSS 10.0): unauthenticated authentication bypass in the Cisco Secure FMC web interface enabling remote root-level script and command execution via crafted HTTP requests; attack surface is limited if the FMC management…
  • CVE-2026-20316 (CVSS 5.3): static hard-coded credentials allow low-privileged unauthenticated logins; chainable with CVE-2026-20079 for privilege escalation.
  • CISA added CVE-2026-20079 to the KEV catalog on September 9, 2026, with a September 12, 2026 remediation deadline for FCEB agencies; CVE-2026-20316 was added to KEV in late July 2026.
  • Three Talos-tracked clusters: UAT-12197 (home.jsp JSP web shell, cmd.jar executor, OmniQuery.pl credential theft from internal databases); UAT-11823 (Sandworm-overlapping APT, Netcat reverse shell, Cyclops Blink variant delivered via…
  • Shared IOCs, identical hot fixes, and a July 23, 2026 log entry indicate both CVE-2026-20079 and CVE-2026-20316 were used in the same attacks.
  • Per SecurityWeek, this is the third FMC vulnerability in KEV this year after CVE-2026-20316 and CVE-2026-20131, both exploited as zero-days earlier in 2026.
  • Mitigations: hotfixes and cloud fixes are available; no workarounds exist; hot fixes do not clean already-compromised devices; keep the FMC management interface off the internet; a comprehensive hardening release is due the week of…
  • Timeline discrepancy: BleepingComputer dates Cisco's exploitation confirmation to August 2026, while SecurityWeek says it came in the September 9, 2026 advisory, with the flaw patched in early March and IOCs added in late July.

Coverage timeline

  1. · 7d ago
    Cisco Security Advisories· 18
    Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

    Cisco will publish security advisories with fixed software on September 16, 2026, covering BroadWorks, ISE, Nexus Dashboard, ASA, FMC, FTD and ThousandEyes.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20131
Unauthenticated Java Deserialization RCE in Cisco FMC and SCC

CVE-2026-20131 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can trigger it by sending crafted serialized data to the exposed management interface. Successful exploitation allows the attacker to execute arbitrary Java code as root on the affected device, giving full control of the central platform that manages Cisco firewall policy. Any organization running FMC or managing firewalls through SCC is potentially affected; specific version ranges have not yet been published in the available data. The flaw was added to CISA KEV on 2026-03-19 with known ransomware use, and EPSS assigns a ~31% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

Do: Check Cisco's advisory for fixed releases and upgrade all FMC and SCC-managed deployments as soon as patched versions are identified, since version ranges are not yet in this data; until patched, restrict the FMC/SCC web-based management interface to trusted management networks or VPN access. Given the CISA KEV listing (added 2026-03-19) with known ransomware use, treat this as a high-priority patch and confirm whether BOD 22-01 remediation deadlines apply to your organization.

10.033% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC) Software version ranges not yet published in available data
  • Cisco Security Cloud Control (SCC) Firewall Management version ranges not yet published in available data
largetens of thousands of FMC/SCC management deployments (10k–100k systems), with a smaller subset of management interfaces internet-exposed
CVE-2026-20316
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).

Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29.

5.311% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC)
largeplausibly tens of thousands of FMC deployments worldwide (no published install base)