Key Takeaways
- Cisco Talos has linked active attacks on FMC systems to three intrusion clusters, including Sandworm and a Qilin ransomware operator
- CVE-2026-20079 carries a CVSS score of 10.0 and can give an unauthenticated remote attacker root access
- Organizations should apply Cisco's available hotfixes now and investigate exposed FMC systems for signs of compromise
Cisco is warning customers to act quickly after confirming active exploitation of two vulnerabilities in the web interface of Cisco Secure Firewall Management Center, or FMC. The product centrally manages firewall policies and multiple Cisco Secure Firewall devices, which makes a compromised installation an unusually valuable foothold.
The vulnerabilities are CVE-2026-20079 and CVE-2026-20316. Both can be exploited remotely without prior authentication, although they work differently and provide attackers with different initial privileges.
CVE-2026-20079 is the more severe of the pair. Cisco assigned it a CVSS score of 10.0, reflecting the prospect of root-level access from a remote attack. The authentication bypass results from an improper system process created when FMC boots. By sending crafted HTTP requests to an unpatched device, an attacker can execute scripts and commands with root privileges.
Internal security testing uncovered CVE-2026-20079. Cisco fixed and disclosed the flaw in early March 2026. A CISA's Known Exploited Vulnerabilities action on September 9 confirmed that exploitation is no longer theoretical and elevated the flaw within vulnerability-remediation programs, particularly for federal agencies subject to KEV deadlines.
CVE-2026-20316, meanwhile, stems from static credentials associated with a low-privileged account. Security researchers reported the issue, and Cisco released a fix on July 29. CISA added that vulnerability to its Known Exploited Vulnerabilities catalog the same day. An unauthenticated attacker can use the hard-coded credentials to log in remotely to an affected FMC instance.
Low privilege does not necessarily mean low impact. Once inside a centralized security-management system, an attacker can conduct reconnaissance, collect credentials and look for routes into the wider environment. Why attack individual firewalls when the management layer may provide visibility across many of them?
Cisco Talos reporting summarized by Help Net Security describes three intrusion clusters using one or both flaws. In the first, attackers exploit CVE-2026-20079 and place a web shell in the CSM Tomcat webroot directory. They then add a malicious JAR file that supports command execution and the theft of authentication data and credentials.
The second cluster is believed to involve Sandworm, the Russian state-sponsored group. After entering through one of the vulnerabilities, the attackers replace the license.tmp file with a malicious copy and establish a reverse shell to command-and-control infrastructure. They collect managed firewall configuration files and install an implant capable of credential harvesting, command and file execution, packet sniffing, and network scanning.
A third cluster, suspected to involve a Qilin ransomware operator, begins with the static credentials exposed by CVE-2026-20316. The operator conducts network and endpoint reconnaissance, steals credentials, creates additional access paths, deploys tools intended to disable antivirus defenses and ultimately delivers ransomware. One management product faces exploitation from two very different motives: intelligence collection and financial extortion.
The activity broadly maps to MITRE ATT&CK stages such as initial access, privilege escalation, credential access and lateral movement. More importantly for security leaders, it shows why exploited edge and management-system vulnerabilities deserve priority over flaws ranked only by theoretical severity.
Cisco has released hotfixes for affected versions of both vulnerabilities and has advised customers to install them as soon as possible. A Canadian Centre for Cyber Security advisory also documented Cisco's security update for the FMC issue. Cisco plans a broader hardening release in mid-September, incorporating the hotfixes and fixes for other internally discovered vulnerabilities. Waiting for that package carries added exposure because attacks are already underway.
Cisco's advisory says CVE-2026-20079 has no workaround, so patching remains the only remediation path. Restricting the FMC management interface from the internet can reduce immediate exposure, but it does not remove the underlying defect or address an existing compromise. Security teams should also review Cisco Talos indicators, inspect the CSM Tomcat webroot and license.tmp file, search for unexpected JAR files or implants, and rotate credentials accessible through FMC. For affected enterprises, this is both a patching event and an incident-hunting exercise.
⬇️