Organizations Warned of Cisco Secure FMC Exploitation
Cisco has warned organizations about a critical vulnerability in their Secure Firewall Management Center (FMC) that has been actively exploited by various threat actors, including state-sponsored groups and ransomware gangs. The vulnerability, CVE-2026-20079, allows unauthenticated remote script execution and can lead to root access. Cisco has released patches, and CISA has added the vulnerability to its list of known exploited vulnerabilities, urging agencies to address it.
Cisco has issued a security advisory regarding a critical vulnerability in its Secure Firewall Management Center (FMC) that has been actively exploited. The vulnerability, tracked as CVE-2026-20079, is a critical authentication bypass issue, enabling unauthenticated remote script execution and potentially granting root access to underlying operating systems.
Cisco patched the vulnerability in early March, and updated its advisory in late July to include Indicators of Compromise (IoCs). However, it wasn't until September 9th that Cisco explicitly stated that active exploitation of CVE-2026-20079 was occurring in August.
CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, directing federal agencies to address the issue by September 12th. Cisco recommends installing available patches and restricting internet access to the FMC interface to mitigate risk.
Talos research and threat intelligence group has identified three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316. One cluster, tracked as UAT-12197, involved exploiting CVE-2026-20079 and deploying a web shell to deliver a malicious JAR file, enabling attackers to steal user authentication data and credentials.
The second cluster, UAT-11823, is linked to the Russian APT group Sandworm, who exploited both FMC vulnerabilities and deployed the Cyclops Blink malware. Cyclops Blink allows operators to download/upload files, harvest credentials, execute arbitrary files and commands, and scan the network.
The third activity cluster, UAT-11988, is believed to be connected to the Qilin ransomware group, who exploited CVE-2026-20316 to gain access to targeted FMC devices, performing reconnaissance, stealing credentials, and creating a list of endpoints for potential encryption.