ZeroHour
Story · 5 sources · 6 articlesfirst updated ()

Critical Cisco FMC Flaws CVE-2026-20079 and CVE-2026-20316 Exploited for Root Access to Deploy Cyclops Blink and Qilin Ransomware

criticalExploit / PoCexploited in the wildimportance 90CVE-2026-20079CVE-2026-20316
What's new: September 10, 2026: Cisco Talos disclosed active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure FMC by three clusters (UAT-12197, UAT-11823, UAT-11988), including chaining of the flaws to deploy Cyclops Blink and Qilin ransomware. CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 remediation deadline for federal agencies (CVE-2026-20316 was listed in late…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Cisco Talos confirmed three clusters — a Sandworm-linked group, a Qilin ransomware affiliate and a credential-harvesting crew — exploiting CVE-2026-20079 (CVSS 10.0) and CVE-2026-20316 (CVSS 5.3) in Cisco Secure Firewall Management Center for root access,…

Cisco Talos reported in-the-wild exploitation of two recently patched flaws in Cisco Secure Firewall Management Center (FMC): CVE-2026-20079 (CVSS 10.0), an unauthenticated web-interface authentication bypass that lets attackers hijack an unclaimed boot session and execute scripts as root, and CVE-2026-20316 (CVSS 5.3), which permits login via a hard-coded static low-privileged account and can be chained for privilege escalation and sensitive-data access. Talos identified three post-compromise clusters: UAT-12197, which deployed JSP web shells (home.jsp) and a cmd.jar command executor to extract credentials from internal databases via OmniQuery.pl; UAT-11823, attributed to Russia's Sandworm, which used a Netcat reverse shell and configuration-harvesting scripts before deploying a Cyclops Blink variant (dropped via a malicious license.tmp file) with init.d persistence, DoH C2 and credential harvesting; and UAT-11988, a Qilin affiliate that used static credentials, living-off-the-land FMC tooling, Active Directory enumeration, impacket, Invoke-TheHash, SOCKS5 proxies, reverse-SSH tunnels and custom AV killers before deploying Qilin ransomware. Cisco released hotfixes and urges immediate installation, with a broader hardening release planned for the week of September 14, 2026. CISA listed CVE-2026-20079 in the KEV catalog with a September 12, 2026 remediation deadline for US federal (FCEB) agencies; most reports say CVE-2026-20316 was added in late July 2026, though one report states both were added with the September 12 deadline. On September 14, 2026, Sophos CTU detailed a new 64-bit x86-64 Cyclops Blink implant (timezone_check) found on FMC appliances compromised via the same two flaws, assessed with high confidence as Russian-nexus and linked with moderate confidence to Sandworm (IRON VIKING, also tracked as Seashell Blizzard).

  • CVE-2026-20079 (CVSS 10.0) is an unauthenticated authentication bypass in Cisco Secure FMC that lets attackers hijack an unclaimed boot session and execute scripts with root privileges.
  • CVE-2026-20316 (CVSS 5.3) permits remote login via a hard-coded static low-privileged account, enabling sensitive-data access and privilege escalation when chained with CVE-2026-20079.
  • Cisco Talos tracked three post-compromise clusters: UAT-12197 (web shells and credential theft), UAT-11823 (Sandworm-linked, Cyclops Blink) and UAT-11988 (Qilin ransomware affiliate).
  • UAT-12197 deployed a home.jsp JSP web shell and a cmd.jar command executor, extracting credentials from internal databases via OmniQuery.pl.
  • UAT-11823, tied to Russia's Sandworm, used a Netcat reverse shell and configuration-harvesting scripts and deployed a Cyclops Blink variant via a malicious license.tmp file, with init.d persistence, DoH C2 and credential harvesting.
  • UAT-11988 used the static-credential flaw for reconnaissance, performed AD enumeration and credential theft with impacket, Invoke-TheHash, SOCKS5 proxies, reverse-SSH tunnels and custom AV killers, then deployed Qilin ransomware.
  • Cisco released hotfixes for both flaws and urges immediate installation; a broader hardening release is planned for the week of September 14, 2026.
  • CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 patch deadline for US federal (FCEB) agencies; per most reports CVE-2026-20316 was added in late July 2026, though one report says both were added with the September 12…

Coverage timeline

  1. · 6d ago
    Cyber Security News· 82
    Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware

    State-sponsored and ransomware actors actively exploit critical Cisco FMC flaws CVE-2026-20079 (CVSS 10.0) and CVE-2026-20316 to gain root access and deploy ransomware.

  2. · 6d ago
    BleepingComputer· 82
    Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

    Cisco Talos confirms ransomware and state-sponsored groups exploited CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center, deploying Qilin ransomware and Cyclops Blink.

  3. · 6d ago
    GBHackers· 87
    Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware

    Threat actors actively exploit Cisco FMC CVE-2026-20079 (CVSS 10.0) for root access, with clusters linked to Sandworm and Qilin ransomware.

  4. · 6d ago
    The Hacker News· 84
    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Three threat clusters including a Sandworm-linked group and Qilin ransomware operators exploit Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316.

  5. · 6d ago
    Security Affairs· 90
    Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

    Three threat groups, including Qilin ransomware operators, exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 for root access, credential theft, and ransomware.

  6. · 3d ago
    GBHackers· 78
    Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities

    Sophos uncovers a 64-bit Cyclops Blink variant on hacked Cisco FMC appliances, adding internal network scanning and selective packet capture; linked to Sandworm.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20316
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).

Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29.

5.311% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC)
largeplausibly tens of thousands of FMC deployments worldwide (no published install base)