Organizations Warned of Cisco Secure FMC Exploitation
Cisco FMC vulnerability CVE-2026-20079 is being actively exploited by multiple threat groups.
Summary
Cisco and CISA have warned of active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC). The vulnerability allows remote attackers to gain root access and has been exploited by at least three distinct activity clusters, including state-sponsored actors and financially motivated groups. Cisco has released patches, and users are advised to install them and restrict internet access to the FMC interface.
Full text
Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year. The security hole, tracked as CVE-2026-20079, is a critical authentication bypass issue that a remote, unauthenticated attacker can exploit to run malicious scripts on vulnerable devices, enabling root access to the underlying OS. “This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device,” Cisco said in an advisory. Cisco patched the vulnerability in early March, and in late July it updated the advisory for CVE-2026-20079 with indicators of compromise (IoCs). However, it did not explicitly warn about active exploitation at the time. The tech giant updated its advisory again on September 9, saying that it became aware of the active exploitation of CVE-2026-20079 in August. CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, instructing federal agencies to address it by September 12.Advertisement. Scroll to continue reading. Cisco FMC users can defend against attacks by installing the available patches. In addition, ensuring that the FMC interface cannot be accessed from the internet significantly reduces the risk of exploitation. CVE-2026-20079 is the third FMC vulnerability added to CISA’s KEV list in 2026, after CVE-2026-20316 and CVE-2026-20131, which threat actors exploited as zero-days. Attacks exploiting CVE-2026-20079 and CVE-2026-20316 Cisco’s Talos research and threat intelligence group reported on Wednesday that it’s aware of three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored threat actors and financially motivated groups. One of the clusters, tracked by Talos as UAT-12197, exploited CVE-2026-20079 and deployed a web shell, which was used to deliver a malicious JAR file. This file then enabled the attacker to obtain user authentication data and credentials from the compromised system. The second cluster is tracked as UAT-11823, which Talos has tied to the Russian APT known as Sandworm. This group exploited both FMC vulnerabilities and delivered the Cyclops Blink malware. The Cyclops Blink sample observed by Talos in these attacks enables its operator to download/upload files, harvest credentials, execute arbitrary files and commands, and scan the network. The third activity cluster is UAT-11988, believed to be connected to the Qilin ransomware. This threat actor exploited CVE-2026-20316 to gain access to targeted FMC devices, performing reconnaissance, stealing credentials, and creating a list of endpoints that can be targeted for encryption. Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day Related: MikroTik Patches Critical Flaws Chained to Hack Routers Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Rockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsAnthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsOpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-DaysSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksExperiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of DollarsCritical JFrog Artifactory Vulnerability Reportedly Exploited in the WildPaperCut Exploitation Escalates to Active IntrusionsNightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Latest News Widened Scan Turns Up Fourth Rogue Claude Cyber Incident4.1 Million Impacted by AdaptHealth Data BreachNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksHelmGuard Raises $7.3 Million for Agentic GRC and SecurityAI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google WarnsAndroid’s September 2026 Updates Patch 180 VulnerabilitiesChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveFrank Verdecanna has been appointed Chief Financial Officer at Armadin.Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.Skyhigh Security has named Anthony Palladino as Chief Operating Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-20079
- cve — CVE-2026-20316
- cve — CVE-2026-20131
- malware — Cyclops Blink
- malware — Qilin ransomware