Cisco’s Secure Firewall Management Center (FMC) Software has been compromised through two critical security vulnerabilities, according to a recent report by Cisco Talos. These weaknesses have been exploited by state-sponsored cybercriminals and a ransomware group to gain root access, install malware, and conduct various attacks on enterprise networks.
Details of the Exploited Vulnerabilities
The primary concern revolves around a vulnerability designated as CVE-2026-20079, which has been assigned a perfect severity score of 10.0 on the CVSS scale. This flaw allows unauthorized remote attackers to bypass authentication controls completely. The issue originates from an improperly generated system process that occurs during the booting of an FMC device. If a legitimate user does not claim the session, attackers can seize it to execute scripts with root-level privileges.
Cisco addressed this vulnerability in March 2026, but it was not until September that the company acknowledged its active exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also recognized this vulnerability as critical, including it in its Known Exploited Vulnerabilities catalog and mandating federal agencies to apply fixes by September 12.
Additional Security Concerns
The second vulnerability, identified as CVE-2026-20316, scored a lower 5.3 on the CVSS scale. It involves hard-coded, static credentials associated with a low-privileged account, enabling remote attackers to access the system without proper authorization. Although this bug provides limited access on its own, it poses a significant risk when combined with other FMC vulnerabilities, allowing for privilege escalation.
This issue was disclosed and patched by Cisco in July 2026, and CISA added it to the KEV catalog around the same time. Cisco Talos researchers have documented three distinct clusters of post-compromise activities, each demonstrating different objectives of the threat actors involved.
Identified Threat Actors and Their Tactics
One cluster, identified as UAT-12197, used the authentication bypass to install a JSP-based web shell within the FMC’s Tomcat directory, followed by deploying a Java Archive command executor named ‘cmd.jar’ to extract stored user credentials.
Another group, UAT-11823, linked to the Russian military-affiliated Sandworm group, combined both CVE vulnerabilities to replace a legitimate license file with a malicious package. This allowed them to establish a Netcat-based reverse shell, exfiltrate device configurations, and deploy a variant of the Cyclops Blink malware.
The final cluster, UAT-11988, associated with the Qilin ransomware group, bypassed the authentication entirely, utilizing the static-credential flaw to access systems. They exploited built-in FMC tools to further infiltrate networks, targeting domain controllers and file servers, eventually deploying the Qilin ransomware.
Immediate Security Recommendations
Cisco and Talos are urging all organizations utilizing Secure FMC to implement the available hotfixes for both CVE-2026-20079 and CVE-2026-20316 without delay, instead of waiting for a comprehensive security update scheduled for mid-September. This update will include additional internal patches.
In the interim, administrators unable to patch immediately should restrict FMC management interfaces from internet exposure to reduce the risk of exploitation from these vulnerabilities. This proactive measure significantly decreases the attack surface for the campaigns observed.
