Cisco Secure FMC flaw CVE-2026-20079 (CVSS 10.0) actively exploited by Sandworm- and Qilin-linked actors; CISA sets September 12, 2026 patch deadline
Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 unauthenticated authentication bypass enabling root-level code execution in Secure Firewall Management Center, used alongside CVE-2026-20316 (CVSS 5.3, static hard-coded credentials). Cisco…
Cisco confirmed in its September 9, 2026 advisory that CVE-2026-20079, a maximum-severity (CVSS 10.0) unauthenticated authentication bypass in the Secure Firewall Management Center (FMC) web interface, is being exploited in the wild. The flaw allows remote, unauthenticated attackers to run malicious scripts and gain root access via crafted HTTP requests; one report describes attackers hijacking an unclaimed boot session. It is being chained with CVE-2026-20316 (CVSS 5.3), a static hard-coded credential flaw enabling unauthenticated low-privileged login, with shared IOCs and a July 23 log entry indicating both flaws were used in the same attacks. Cisco Talos identified three post-compromise clusters: UAT-12197 (home.jsp web shell, cmd.jar executor, OmniQuery.pl database credential theft), UAT-11823 (high-confidence Sandworm-linked, deploying Netcat reverse shells and a Cyclops Blink variant via a malicious license.tmp file), and UAT-11988 (a Qilin ransomware affiliate using AD enumeration, credential theft, AV killers, and living-off-the-land FMC tooling before ransomware deployment). Sophos CTU subsequently analyzed a 64-bit x86-64 Cyclops Blink implant ('timezone_check') with network-scanning and packet-capture modules, attributed with high confidence to a Russian nexus and with moderate confidence to Sandworm (IRON VIKING/Seashell Blizzard). CISA added the flaws to KEV requiring federal civilian agencies to remediate by September 12, 2026. Cisco urges immediate hotfix installation, warns hot fixes do not clean already-compromised devices, says no workarounds exist, and recommends keeping the FMC management interface off the internet pending a broader hardening release in mid-September.
- CVE-2026-20079 is a CVSS 10.0 unauthenticated authentication bypass in the Cisco Secure FMC web interface, enabling root-level script and command execution via crafted HTTP requests; one report specifies attackers hijack an unclaimed boot…
- CVE-2026-20316 (CVSS 5.3) stems from static hard-coded credentials allowing unauthenticated login with a low-privileged account and can be chained with CVE-2026-20079 for privilege escalation.
- Cisco patched CVE-2026-20079 in early March 2026 and published IOCs in late July, but only confirmed active exploitation in its September 9, 2026 advisory; shared IOCs and a July 23 log entry suggest both flaws were used in the same…
- CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 remediation deadline for federal civilian (FCEB) agencies; sources disagree on CVE-2026-20316's listing (one report says both were added with the September 12 deadline,…
- Cisco Talos identified three post-compromise activity clusters exploiting the flaws: UAT-12197, UAT-11823, and UAT-11988, including state-sponsored and financially motivated actors.
- UAT-12197 deployed a home.jsp JSP web shell and a cmd.jar JAR command executor, extracting credentials from internal databases via OmniQuery.pl.
- UAT-11823, assessed as Sandworm-linked with high confidence, used a Netcat reverse shell and configuration-harvesting scripts and deployed a Cyclops Blink variant with DNS-over-HTTPS C2 and init.d persistence, delivered via a malicious…
- UAT-11988, a Qilin ransomware affiliate, abused the CVE-2026-20316 static credentials, performed AD enumeration and credential theft using tools including impacket and Invoke-TheHash, deployed custom AV killers, SOCKS5 proxies, and…
Coverage timelineoldest first · each row is one article
- · 7d agoCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
BleepingComputer· 85
Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass enabling unauthenticated root command execution in Secure FMC; CISA added it to KEV.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-20131 | Unauthenticated Java Deserialization RCE in Cisco FMC and SCC CVE-2026-20131 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can trigger it by sending crafted serialized data to the exposed management interface. Successful exploitation allows the attacker to execute arbitrary Java code as root on the affected device, giving full control of the central platform that manages Cisco firewall policy. Any organization running FMC or managing firewalls through SCC is potentially affected; specific version ranges have not yet been published in the available data. The flaw was added to CISA KEV on 2026-03-19 with known ransomware use, and EPSS assigns a ~31% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. Do: Check Cisco's advisory for fixed releases and upgrade all FMC and SCC-managed deployments as soon as patched versions are identified, since version ranges are not yet in this data; until patched, restrict the FMC/SCC web-based management interface to trusted management networks or VPN access. Given the CISA KEV listing (added 2026-03-19) with known ransomware use, treat this as a high-priority patch and confirm whether BOD 22-01 remediation deadlines apply to your organization. | 10.0 | 33% | KEV ransomware |
| largetens of thousands of FMC/SCC management deployments (10k–100k systems), with a smaller subset of management interfaces internet-exposed | |
| CVE-2026-20316 | Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile). Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29. | 5.3 | 11% | KEV ransomware |
| largeplausibly tens of thousands of FMC deployments worldwide (no published install base) |