Sandworm-linked APT and Qilin ransomware affiliates exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316
Cisco Talos is tracking three post-compromise clusters — including a Sandworm-linked APT deploying Cyclops Blink and a Qilin ransomware operator — actively exploiting CVE-2026-20079 (CVSS 10.0), an unauthenticated root command-execution bypass in Cisco Secure…
Cisco Talos is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC), the platform that centrally manages Cisco Secure Firewall deployments — an exposure SOCRadar notes is likely widespread across enterprises. CVE-2026-20079 (CVSS 10.0) is an unauthenticated authentication bypass in the FMC web interface: an attacker sends crafted HTTP requests to bypass authentication and execute scripts and commands with root privileges on the underlying operating system. The flaw stems from an improper system process created at boot time, which Cyber Security News describes as attackers hijacking an unclaimed boot session. CVE-2026-20316 (CVSS 5.3) stems from static hard-coded credentials that allow low-privileged, unauthenticated logins and can be chained for privilege escalation. Shared IOCs, identical hotfixes, and a July 23 log entry suggest the two flaws were used in the same attacks (BleepingComputer). On timing, SecurityWeek reports Cisco patched CVE-2026-20079 in early March 2026 and published IOCs in late July, but sources differ on when Cisco confirmed active exploitation: BleepingComputer dates the confirmation to August 2026, while SecurityWeek places it in Cisco's September 9, 2026 advisory. CISA added CVE-2026-20079 to the Known Exploited Vulnerabilities catalog, ordering federal civilian (FCEB) agencies to remediate by September 12, 2026; The Hacker News reports CVE-2026-20316 was added to KEV in late July 2026, whereas Cyber Security News describes both CVEs as listed with the September 12 deadline (sources disagree). SecurityWeek notes this is the third FMC vulnerability added to KEV this year, after CVE-2026-20316 and CVE-2026-20131, both flagged as exploited as zero-days earlier in 2026. Cisco Talos identified three post-compromise clusters. UAT-12197 deployed a home.jsp JSP web shell and a cmd.jar JAR command executor, querying internal databases (including via OmniQuery.pl, per GBHackers) to steal credentials. UAT-11823, attributed with high confidence to a Sandworm-linked APT (GBHackers; Talos describes an overlap), deployed a Netcat reverse shell, configuration-harvesting scripts, and a Cyclops Blink variant previously attributed to Russia's Sandworm (The Hacker News), reportedly delivered via a malicious license.tmp file (BleepingComputer), with init.d persistence and DNS-over-HTTPS C2 (GBHackers, Cyber Security News); Cyber Security News says this cluster chained both CVEs. UAT-11988 was assessed…
- CVE-2026-20079 (CVSS 10.0) is an unauthenticated authentication bypass in the Cisco Secure FMC web interface that lets remote attackers execute scripts and commands as root via crafted HTTP requests.
- CVE-2026-20316 (CVSS 5.3) stems from static hard-coded credentials permitting low-privileged, unauthenticated logins that can be chained for privilege escalation.
- Shared IOCs, identical hotfixes, and a July 23, 2026 log entry suggest CVE-2026-20079 and CVE-2026-20316 were used in the same attacks (BleepingComputer).
- CISA added CVE-2026-20079 to the KEV catalog, requiring FCEB/federal agencies to patch by September 12, 2026.
- Sources disagree on CVE-2026-20316's KEV status: The Hacker News says it was added in late July 2026, while Cyber Security News says both CVEs were added with the September 12 deadline.
- This is the third FMC vulnerability added to KEV in 2026, after CVE-2026-20316 and CVE-2026-20131, both exploited as zero-days earlier in the year (SecurityWeek).
- UAT-12197 deployed a home.jsp JSP web shell and cmd.jar command executor, querying internal databases via OmniQuery.pl to steal credentials.
- UAT-11823, attributed with high confidence to a Sandworm-linked APT, deployed a Netcat reverse shell and a Cyclops Blink variant (delivered via a malicious license.tmp file) with init.d persistence and DNS-over-HTTPS C2.
Coverage timelineoldest first · each row is one article
- · 6d agoCisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
Cisco Security Advisories· 78
Cisco warns of a critical authentication bypass in Secure Firewall Management Center that lets unauthenticated attackers execute scripts and obtain root access.
- · 6d agoActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos· 90
Cisco Talos reports in-the-wild exploitation of critical FMC flaw CVE-2026-20079 by three clusters including a Sandworm-linked APT and Qilin ransomware affiliates.
- · 6d agoCisco security advisory (AV26-197) – Update 3
Canadian Centre for Cyber Security· 68
CISA added Cisco CVE-2026-20079 to its KEV catalog; the Canadian Cyber Centre urges updates across Secure Firewall ASA, FTD, FMC, and SCC products.
- · 5d agoCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
BleepingComputer· 85
Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass enabling unauthenticated root command execution in Secure FMC; CISA added it to KEV.
- · 5d agoOrganizations Warned of Cisco Secure FMC Exploitation
SecurityWeek· 88
Cisco and CISA warn that critical FMC authentication bypass CVE-2026-20079 is actively exploited; CISA added it to the KEV catalog with a September 12 deadline.
- · 5d agoCisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
Help Net Security· 88
Cisco Talos confirms nation-state (Sandworm) and ransomware (Qilin) actors actively exploit CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center.
- · 5d agoCisco FMC CVE-2026-20079 Actively Exploited
SOCRadar· 85
Cisco confirms active exploitation of CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center.
- · 5d agoHackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cyber Security News· 82
State-sponsored and ransomware actors actively exploit critical Cisco FMC flaws CVE-2026-20079 (CVSS 10.0) and CVE-2026-20316 to gain root access and deploy ransomware.
- · 5d agoCisco FMC flaws exploited by ransomware gang, state-sponsored hackers
BleepingComputer· 82
Cisco Talos confirms ransomware and state-sponsored groups exploited CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center, deploying Qilin ransomware and Cyclops Blink.
- · 4d agoCritical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware
GBHackers· 87
Threat actors actively exploit Cisco FMC CVE-2026-20079 (CVSS 10.0) for root access, with clusters linked to Sandworm and Qilin ransomware.
- · 4d agoCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
The Hacker News· 84
Three threat clusters including a Sandworm-linked group and Qilin ransomware operators exploit Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316.
- · 4d agoAttackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Security Affairs· 90
Three threat groups, including Qilin ransomware operators, exploit critical Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 for root access, credential theft, and ransomware.
- · 1d agoSandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
GBHackers· 78
Sophos uncovers a 64-bit Cyclops Blink variant on hacked Cisco FMC appliances, adding internal network scanning and selective packet capture; linked to Sandworm.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20079 | Authentication bypass to root access in Cisco Secure Firewall Management Center CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09. Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected. | 10.0 | 76% | KEV PoC ×2 |
| largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands) | |
| CVE-2026-20131 | Unauthenticated Java Deserialization RCE in Cisco FMC and SCC CVE-2026-20131 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management. An unauthenticated, remote attacker can trigger it by sending crafted serialized data to the exposed management interface. Successful exploitation allows the attacker to execute arbitrary Java code as root on the affected device, giving full control of the central platform that manages Cisco firewall policy. Any organization running FMC or managing firewalls through SCC is potentially affected; specific version ranges have not yet been published in the available data. The flaw was added to CISA KEV on 2026-03-19 with known ransomware use, and EPSS assigns a ~31% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. Do: Check Cisco's advisory for fixed releases and upgrade all FMC and SCC-managed deployments as soon as patched versions are identified, since version ranges are not yet in this data; until patched, restrict the FMC/SCC web-based management interface to trusted management networks or VPN access. Given the CISA KEV listing (added 2026-03-19) with known ransomware use, treat this as a high-priority patch and confirm whether BOD 22-01 remediation deadlines apply to your organization. | 10.0 | 33% | KEV ransomware |
| largetens of thousands of FMC/SCC management deployments (10k–100k systems), with a smaller subset of management interfaces internet-exposed | |
| CVE-2026-20316 | Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile). Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29. | 5.3 | 11% | KEV ransomware |
| largeplausibly tens of thousands of FMC deployments worldwide (no published install base) |