Cisco has disclosed that multiple threat actors, including those involved in ransomware and state-backed cyberattacks, have been exploiting two newly patched vulnerabilities in its Secure Firewall Management Center (FMC) software. These vulnerabilities, identified as CVE-2026-20079 and CVE-2026-20316, have been actively targeted, posing significant security risks to affected systems.
Details of the Vulnerabilities
The vulnerability CVE-2026-20079, with a critical CVSS score of 10.0, is particularly concerning. It allows unauthenticated remote attackers to bypass authentication on the FMC web interface, potentially executing scripts to gain root access to the underlying operating system. This flaw poses a severe threat, enabling attackers to control affected devices.
The second vulnerability, CVE-2026-20316, has a CVSS score of 5.3. It permits unauthenticated remote attackers to log in with low-privilege access and obtain sensitive information. When combined with other vulnerabilities in the FMC, it can lead to privilege escalation, further endangering network security.
Identified Threat Clusters
Cisco Talos has identified three threat groups exploiting these vulnerabilities. The first, UAT-12197, uses CVE-2026-20079 to deploy web shells and command executors for internal database queries and credential theft. The second group, UAT-11823, exploits both vulnerabilities to deploy reverse shells and harvest device configurations, linking them to the Russian hacking group Sandworm.
The third cluster, UAT-11988, is a ransomware operation exploiting CVE-2026-20316 for initial access. This group utilizes legitimate FMC tools for reconnaissance, network persistence, and deploying Qilin ransomware, highlighting the sophisticated tactics employed by these attackers.
Mitigation and Prevention Efforts
Cisco has urged customers to apply hotfixes for the affected software versions to mitigate the risks posed by these vulnerabilities. The company is also preparing to release a comprehensive security update addressing internally discovered issues. Meanwhile, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to implement patches promptly.
As cyber threats continue to evolve, it remains crucial for organizations to stay informed and proactive in securing their systems against such exploits. Regular updates and vigilance can help mitigate potential risks and protect critical infrastructure from sophisticated cyberattacks.
