Threat researchers at Cisco Talos are tracking the active exploitation of two critical Cisco FMC vulnerabilities. Malicious actors use these flaws to bypass authentication, deploy persistent malware, and launch ransomware attacks. Organizations must install the latest security updates immediately to protect their firewall management systems.
- Product: Cisco Secure Firewall Management Center (FMC)
- Vulnerabilities: 2 flaws (CVE-2026-20079, CVE-2026-20316)
- Highest severity: 10.0 (Critical · CVSSv3)
- Worst impact: Secure Firewall Management Center Authentication Bypass Remote Code Execution
- Status: Exploited in the wild
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-20079 | 10 | CWE-288 | Exploited in the wild |
| CVE-2026-20316 | 5.3 | CWE-259 | Exploited in the wild |
Why This Threat Matters
Cisco Secure Firewall Management Center acts as the central nervous system for enterprise network defenses. Thousands of organizations rely on this platform to manage security policies and monitor traffic. Consequently, when attackers compromise this management layer, they gain unrestricted access to the entire security infrastructure.
These Cisco FMC vulnerabilities allow threat actors to exfiltrate sensitive configuration data and harvest credentials. According to the Cisco Talos report, advanced persistent threat groups and ransomware affiliates are already abusing these flaws. The attackers use their access to map internal networks and deploy destructive payloads, including the Qilin ransomware. A compromised firewall manager essentially hands the keys to the kingdom directly to cybercriminals.
How the Attack Works
The active campaigns rely on chaining two distinct security flaws. The primary issue, CVE-2026-20079, is an authentication bypass in the web interface. This flaw originates from an improper system process created during boot time. Remote attackers exploit this by sending specially crafted HTTP requests to the device. The advisory states that this allows attackers to “execute scripts on impacted devices to obtain root access to the underlying operating system.”
The second flaw, CVE-2026-20316, involves static user credentials. The software contains a hardcoded low-privileged account. Attackers use these static credentials to log into the system initially. Once authenticated, they escalate their privileges by exploiting the first authentication bypass flaw.
After gaining root access, the attackers deploy various post-compromise tools. In the first observed cluster, tracked as UAT-12197, attackers deployed a JSP-based web shell that decoded Base64 parameters to load Java classes. This allowed them to query internal databases for user authentication data. The second cluster, UAT-11823, used proxy tooling and reverse shells to download Cyclops Blink, an implant capable of packet sniffing and DNS over HTTPS resolution. The third cluster, UAT-11988, established a Python SOCKS5 proxy and a reverse-SSH tunnel to forward ports like LDAP, SMB, and Kerberos back to their own infrastructure.
Affected Versions
These Cisco FMC vulnerabilities impact on-premises deployments of the management software. Affected branches include versions 7.0 through 7.7. Cloud-delivered instances and standalone Adaptive Security Appliance devices remain secure against this specific attack vector. Cisco Talos confirms that multiple threat clusters, including the Russia-linked Sandworm group and Qilin ransomware affiliates, are actively exploiting these bugs in the wild.
Patch and Mitigation Steps
Network administrators must prioritize patching their firewall management systems. Cisco has released hotfixes for all affected software versions. Furthermore, the vendor plans to release an extensive hardening update to address additional internal findings.
There are no official workarounds to mitigate the authentication bypass. You must apply the patches provided in the authentication bypass security advisory and the static credential security advisory. While waiting for deployment, administrators should strictly limit access to the management interface using access control lists and virtual private networks.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!