ZeroHour
Story · 1 source · 1 articlefirst updated ()

Cisco FMC flaws CVE-2026-20079 and CVE-2026-20316 actively exploited by Sandworm and Qilin actors; new 64-bit Cyclops Blink variant emerges

criticalExploit / PoCexploited in the wildimportance 90CVE-2026-20079CVE-2026-20316
What's new: This is the first merged summary for this story. The reporting evolved from Cisco Talos's initial disclosure (September 10-11) of three exploiting clusters (UAT-12197, UAT-11823/Sandworm, UAT-11988/Qilin) to Sophos CTU's September 14 analysis of a new 64-bit x86-64 Cyclops Blink variant ('timezone_check') on compromised FMC appliances, which extends the backdoor beyond WatchGuard devices and adds…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Cisco Talos confirmed in-the-wild exploitation of two Cisco Secure Firewall Management Center flaws: CVE-2026-20079 (CVSS 10.0 unauthenticated authentication bypass enabling root code execution) and CVE-2026-20316 (CVSS 5.3 hard-coded static credentials),…

Cisco Talos identified active exploitation of CVE-2026-20079, a CVSS 10.0 unauthenticated authentication bypass in the Cisco Secure Firewall Management Center (FMC) web interface that allows root-level script and command execution via crafted HTTP requests (reportedly by hijacking an unclaimed boot session), and CVE-2026-20316 (CVSS 5.3), caused by static hard-coded credentials that permit unauthenticated login via a low-privileged static account and can be chained for privilege escalation. Talos tracked three post-compromise clusters: UAT-12197 deployed a home.jsp JSP web shell and a cmd.jar JAR command executor to extract credentials from internal databases via OmniQuery.pl; UAT-11823, assessed with high confidence as a Sandworm-linked APT, chained both flaws to deploy a Netcat reverse shell, configuration-harvesting scripts, and a Cyclops Blink variant (via a malicious license.tmp file) with DoH C2 and init.d persistence; and UAT-11988, a Qilin ransomware affiliate, used the static-credential flaw for access, performed Active Directory enumeration and credential theft with living-off-the-land FMC tooling, SOCKS5 proxies, reverse-SSH tunnels, impacket, Invoke-TheHash, and custom AV killers before deploying Qilin ransomware. Hotfixes are available now and Cisco urges immediate installation, with a broader hardening release planned for mid-September (sources disagree: week of September 14 per GBHackers vs. week of September 16 per Help Net Security); Cisco also advises taking the FMC management interface offline if patching cannot be done immediately. CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 remediation deadline for FCEB agencies; sources disagree on whether CVE-2026-20316 was added at the same time or separately in late July 2026. In a September 14 update, Sophos CTU reported a new 64-bit x86-64 Cyclops Blink implant ('timezone_check') on FMC appliances compromised via both CVEs, assessed with high confidence as Russian-nexus and with moderate confidence as linked to Sandworm (IRON VIKING, also tracked as Seashell Blizzard). The implant runs a parent controller plus five worker modules, masquerades as [kworker/0:1], persists via SysV init scripts at /lib/tz/timezone_check, adds iptables rules, and beacons to hard-coded C2 89.34.96.56 over a custom TLS protocol on ports 43856 and 49172; module 0x11 scans internal IPv4 networks for SSH, SMB, LDAP, VMware, HTTP/HTTPS, and VPN services, while module 0x12 performs filtered packet…

  • CVE-2026-20079 (CVSS 10.0): critical unauthenticated authentication bypass in Cisco FMC's web interface enabling root-level script and command execution via crafted HTTP requests.
  • CVE-2026-20316 (CVSS 5.3): static hard-coded credentials allow unauthenticated login via a low-privileged static account; chainable with CVE-2026-20079 for privilege escalation.
  • Cisco Talos tracked three exploitation clusters: UAT-12197 (JSP web shell home.jsp plus cmd.jar credential harvesting via OmniQuery.pl), UAT-11823 (Sandworm-linked: Netcat reverse shell, configuration harvesting, Cyclops Blink via…
  • Sophos CTU (September 14): new 64-bit x86-64 Cyclops Blink implant 'timezone_check' with a parent controller and five worker modules, [kworker/0:1] masquerade, SysV init persistence at /lib/tz/timezone_check, and hard-coded C2 89.34.96.56…
  • New Cyclops Blink modules: 0x11 scans internal IPv4 networks for SSH, SMB, LDAP, VMware, HTTP/HTTPS, and VPN services; 0x12 performs filtered packet capture that can expose cleartext credentials, cookies, and tokens.
  • Attribution: high-confidence Russian nexus with moderate-confidence link to Sandworm (IRON VIKING, Seashell Blizzard) for the Sophos-analyzed implant; Talos assessed cluster UAT-11823 as a Sandworm-linked APT, while Cyclops Blink was…
  • Remediation: hotfixes available now; broader hardening release due mid-September (sources disagree: week of September 14 vs. week of September 16); Cisco advises taking the FMC management interface offline if immediate patching is not…
  • CISA added CVE-2026-20079 to the KEV catalog with a September 12, 2026 patch deadline for FCEB agencies; sources disagree on whether CVE-2026-20316 was added simultaneously or separately in late July 2026.

Coverage timeline

  1. · 7d ago
    Help Net Security· 88
    Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

    Cisco Talos confirms nation-state (Sandworm) and ransomware (Qilin) actors actively exploit CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20316
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).

Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29.

5.311% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC)
largeplausibly tens of thousands of FMC deployments worldwide (no published install base)