Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities in Cisco Firewall Software Exploited

Critical Vulnerabilities in Cisco Firewall Software Exploited

Posted on September 10, 2026 By CWS

Cisco’s Secure Firewall Management Center (FMC) Software has been compromised through two critical security vulnerabilities, according to a recent report by Cisco Talos. These weaknesses have been exploited by state-sponsored cybercriminals and a ransomware group to gain root access, install malware, and conduct various attacks on enterprise networks.

Details of the Exploited Vulnerabilities

The primary concern revolves around a vulnerability designated as CVE-2026-20079, which has been assigned a perfect severity score of 10.0 on the CVSS scale. This flaw allows unauthorized remote attackers to bypass authentication controls completely. The issue originates from an improperly generated system process that occurs during the booting of an FMC device. If a legitimate user does not claim the session, attackers can seize it to execute scripts with root-level privileges.

Cisco addressed this vulnerability in March 2026, but it was not until September that the company acknowledged its active exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also recognized this vulnerability as critical, including it in its Known Exploited Vulnerabilities catalog and mandating federal agencies to apply fixes by September 12.

Additional Security Concerns

The second vulnerability, identified as CVE-2026-20316, scored a lower 5.3 on the CVSS scale. It involves hard-coded, static credentials associated with a low-privileged account, enabling remote attackers to access the system without proper authorization. Although this bug provides limited access on its own, it poses a significant risk when combined with other FMC vulnerabilities, allowing for privilege escalation.

This issue was disclosed and patched by Cisco in July 2026, and CISA added it to the KEV catalog around the same time. Cisco Talos researchers have documented three distinct clusters of post-compromise activities, each demonstrating different objectives of the threat actors involved.

Identified Threat Actors and Their Tactics

One cluster, identified as UAT-12197, used the authentication bypass to install a JSP-based web shell within the FMC’s Tomcat directory, followed by deploying a Java Archive command executor named ‘cmd.jar’ to extract stored user credentials.

Another group, UAT-11823, linked to the Russian military-affiliated Sandworm group, combined both CVE vulnerabilities to replace a legitimate license file with a malicious package. This allowed them to establish a Netcat-based reverse shell, exfiltrate device configurations, and deploy a variant of the Cyclops Blink malware.

The final cluster, UAT-11988, associated with the Qilin ransomware group, bypassed the authentication entirely, utilizing the static-credential flaw to access systems. They exploited built-in FMC tools to further infiltrate networks, targeting domain controllers and file servers, eventually deploying the Qilin ransomware.

Immediate Security Recommendations

Cisco and Talos are urging all organizations utilizing Secure FMC to implement the available hotfixes for both CVE-2026-20079 and CVE-2026-20316 without delay, instead of waiting for a comprehensive security update scheduled for mid-September. This update will include additional internal patches.

In the interim, administrators unable to patch immediately should restrict FMC management interfaces from internet exposure to reduce the risk of exploitation from these vulnerabilities. This proactive measure significantly decreases the attack surface for the campaigns observed.

Cyber Security News Tags:CISA, Cisco, Cisco Talos, CVE-2026-20079, CVE-2026-20316, Cyberattack, Cybersecurity, Firewall, FMC software, Hackers, Malware, network security, Ransomware, Vulnerabilities

Post navigation

Previous Post: AdaptHealth Data Breach Exposes 4.1 Million Records
Next Post: Citrix NetScaler Vulnerability Sparks Urgent CISA Warning

Related Posts

Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT Cyber Security News
Cybercriminals Exploit Cloud Services for Phishing Cybercriminals Exploit Cloud Services for Phishing Cyber Security News
CrowdStrike Warns of New Mass Exploitation Campaign Leveraging Oracle E-Business Suite 0-Day CrowdStrike Warns of New Mass Exploitation Campaign Leveraging Oracle E-Business Suite 0-Day Cyber Security News
New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data Cyber Security News
Hackers Exploit ChatGPT Links to Deploy Malware on Windows Hackers Exploit ChatGPT Links to Deploy Malware on Windows Cyber Security News
Critical Argument Injection Vulnerability in Popular AI Agents Let Attackers Execute Remote Code Critical Argument Injection Vulnerability in Popular AI Agents Let Attackers Execute Remote Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattacks: Claude Agents Revolutionize Hacking
  • AI Workflow Vulnerability Exploited by Hackers
  • Hackers Exploit Phishing to Compromise Microsoft 365 Accounts
  • Citrix NetScaler Vulnerability Sparks Urgent CISA Warning
  • Critical Vulnerabilities in Cisco Firewall Software Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattacks: Claude Agents Revolutionize Hacking
  • AI Workflow Vulnerability Exploited by Hackers
  • Hackers Exploit Phishing to Compromise Microsoft 365 Accounts
  • Citrix NetScaler Vulnerability Sparks Urgent CISA Warning
  • Critical Vulnerabilities in Cisco Firewall Software Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark