Active Exploitation Found in Cisco Secure FMC Flaw

Cisco and CISA warned threat actors exploited a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) to run scripts and gain root access.
Cisco and the U.S. Cybersecurity and Infrastructure Security Agency warned that attackers have actively exploited a critical authentication bypass in Cisco Secure Firewall Management Center, tracked as CVE-2026-20079. The flaw allows a remote, unauthenticated actor to run malicious scripts and obtain root access on affected devices.
Cisco’s advisory attributes the vulnerability to an improper system process created at boot and says it can be triggered by sending crafted HTTP requests to a vulnerable appliance. The company issued a patch in early March and published indicators of compromise in late July. Cisco updated its advisory on September 9 to report it became aware of active exploitation in August.
CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog and directed federal civilian agencies to address the issue by September 12. The agency’s inclusion in the KEV list signals that the vulnerability is being used in real-world attacks.
Talos, Cisco’s threat intelligence group, reported three distinct activity clusters exploiting CVE-2026-20079 and a related FMC flaw, CVE-2026-20316. The cluster tracked as UAT-12197 used the authentication bypass to install a web shell and then delivered a malicious Java ARchive (JAR) file that harvested user authentication data and credentials from compromised appliances.
A second cluster, UAT-11823, has been linked to the Russian advanced persistent threat known as Sandworm. That cluster chain-deployed exploits against the management center and deployed Cyclops Blink malware. The observed Cyclops Blink samples are capable of downloading and uploading files, harvesting credentials, executing arbitrary files and commands, and scanning networks.
The third cluster, UAT-11988, is believed to be associated with the Qilin ransomware group. Talos reports that this actor exploited CVE-2026-20316 to perform reconnaissance, steal credentials and compile lists of endpoints for potential encryption.
Cisco and CISA recommended that organizations running Secure Firewall Management Center install the available patches promptly. Advisories also note that keeping the FMC management interface off the public internet, using network segmentation and searching for published IoCs on internal systems will reduce the chance of compromise. Security teams are urged to review access controls for management interfaces and apply vendor fixes. Continuous attack surface management can help security teams identify internet-facing management interfaces before attackers exploit them.
CVE-2026-20079 is the third Secure FMC vulnerability added to CISA’s KEV list in 2026, following CVE-2026-20316 and CVE-2026-20131, both of which were exploited as zero-days earlier in the year.








