Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploitation of Cisco FMC Vulnerabilities Unveiled

Exploitation of Cisco FMC Vulnerabilities Unveiled

Posted on September 11, 2026 By CWS

Cisco has disclosed that multiple threat actors, including those involved in ransomware and state-backed cyberattacks, have been exploiting two newly patched vulnerabilities in its Secure Firewall Management Center (FMC) software. These vulnerabilities, identified as CVE-2026-20079 and CVE-2026-20316, have been actively targeted, posing significant security risks to affected systems.

Details of the Vulnerabilities

The vulnerability CVE-2026-20079, with a critical CVSS score of 10.0, is particularly concerning. It allows unauthenticated remote attackers to bypass authentication on the FMC web interface, potentially executing scripts to gain root access to the underlying operating system. This flaw poses a severe threat, enabling attackers to control affected devices.

The second vulnerability, CVE-2026-20316, has a CVSS score of 5.3. It permits unauthenticated remote attackers to log in with low-privilege access and obtain sensitive information. When combined with other vulnerabilities in the FMC, it can lead to privilege escalation, further endangering network security.

Identified Threat Clusters

Cisco Talos has identified three threat groups exploiting these vulnerabilities. The first, UAT-12197, uses CVE-2026-20079 to deploy web shells and command executors for internal database queries and credential theft. The second group, UAT-11823, exploits both vulnerabilities to deploy reverse shells and harvest device configurations, linking them to the Russian hacking group Sandworm.

The third cluster, UAT-11988, is a ransomware operation exploiting CVE-2026-20316 for initial access. This group utilizes legitimate FMC tools for reconnaissance, network persistence, and deploying Qilin ransomware, highlighting the sophisticated tactics employed by these attackers.

Mitigation and Prevention Efforts

Cisco has urged customers to apply hotfixes for the affected software versions to mitigate the risks posed by these vulnerabilities. The company is also preparing to release a comprehensive security update addressing internally discovered issues. Meanwhile, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to implement patches promptly.

As cyber threats continue to evolve, it remains crucial for organizations to stay informed and proactive in securing their systems against such exploits. Regular updates and vigilance can help mitigate potential risks and protect critical infrastructure from sophisticated cyberattacks.

The Hacker News Tags:CISA, Cisco, CVE-2026-20079, CVE-2026-20316, Cybersecurity, FMC, Ransomware, Secure Firewall Management Center, state-sponsored attacks, Vulnerabilities

Post navigation

Previous Post: GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
Next Post: Kiteworks Enhances Data Security with Bonfy.AI Acquisition

Related Posts

Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks The Hacker News
ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections ClickFix Malware Campaign Exploits CAPTCHAs to Spread Cross-Platform Infections The Hacker News
CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV The Hacker News
A 24-Hour Timeline of a Modern Stealer Campaign A 24-Hour Timeline of a Modern Stealer Campaign The Hacker News
Securing the Open Android Ecosystem with Samsung Knox Securing the Open Android Ecosystem with Samsung Knox The Hacker News
Critical Flaw in Funnel Builder Targets WooCommerce Critical Flaw in Funnel Builder Targets WooCommerce The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SloppyRAT Malware: New Tactics via ClickFix Uncovered
  • Ukrainian Hacker Sentenced for Role in Conti Ransomware
  • IDScan Data Breach: 153M Driver’s Licenses Exposed
  • Kiteworks Enhances Data Security with Bonfy.AI Acquisition
  • Exploitation of Cisco FMC Vulnerabilities Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SloppyRAT Malware: New Tactics via ClickFix Uncovered
  • Ukrainian Hacker Sentenced for Role in Conti Ransomware
  • IDScan Data Breach: 153M Driver’s Licenses Exposed
  • Kiteworks Enhances Data Security with Bonfy.AI Acquisition
  • Exploitation of Cisco FMC Vulnerabilities Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark