Organizations Warned of Cisco Secure FMC Exploitation

CriticalCVSS 10.0SecurityWeek · Eduard Kovacs·

At a glance

Severity
CriticalCVSS 10.0
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-20079
Vendors and products
Cisco
Industries
Government
Reported by
1 outlet

Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year.

The security hole, tracked as CVE-2026-20079, is a critical authentication bypass issue that a remote, unauthenticated attacker can exploit to run malicious scripts on vulnerable devices, enabling root access to the underlying OS.

“This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device,” Cisco said in an advisory.

Cisco patched the vulnerability in early March, and in late July it updated the advisory for CVE-2026-20079 with indicators of compromise (IoCs). However, it did not explicitly warn about active exploitation at the time.

The tech giant updated its advisory again on September 9, saying that it became aware of the active exploitation of CVE-2026-20079 in August.

CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, instructing federal agencies to address it by September 12.

Advertisement. Scroll to continue reading.

Cisco FMC users can defend against attacks by installing the available patches. In addition, ensuring that the FMC interface cannot be accessed from the internet significantly reduces the risk of exploitation.

CVE-2026-20079 is the third FMC vulnerability added to CISA’s KEV list in 2026, after CVE-2026-20316 and CVE-2026-20131, which threat actors exploited as zero-days.

Attacks exploiting CVE-2026-20079 and CVE-2026-20316

Cisco’s Talos research and threat intelligence group reported on Wednesday that it’s aware of three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored threat actors and financially motivated groups.

One of the clusters, tracked by Talos as UAT-12197, exploited CVE-2026-20079 and deployed a web shell, which was used to deliver a malicious JAR file. This file then enabled the attacker to obtain user authentication data and credentials from the compromised system.

The second cluster is tracked as UAT-11823, which Talos has tied to the Russian APT known as Sandworm. This group exploited both FMC vulnerabilities and delivered the Cyclops Blink malware. 

The Cyclops Blink sample observed by Talos in these attacks enables its operator to download/upload files, harvest credentials, execute arbitrary files and commands, and scan the network. 

The third activity cluster is UAT-11988, believed to be connected to the Qilin ransomware. This threat actor exploited CVE-2026-20316 to gain access to targeted FMC devices, performing reconnaissance, stealing credentials, and creating a list of endpoints that can be targeted for encryption.

Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Related: MikroTik Patches Critical Flaws Chained to Hack Routers

Reproduced in full under licence from SecurityWeek. © SecurityWeek. Written by Eduard Kovacs.

Vulnerabilities referenced

  • CVE-2026-2007910.0Critical

    Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

    Used in attacks

    Added to CISA's list 2026-09-09 · Exploit code published · Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. SecurityWeekEstablished SourceFirst reported

    2026-09-10 10:06 UTC

Related stories