SecurityWeek

Organizations Warned of Cisco Secure FMC Exploitation


Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year.

The security hole, tracked as CVE-2026-20079, is a critical authentication bypass issue that a remote, unauthenticated attacker can exploit to run malicious scripts on vulnerable devices, enabling root access to the underlying OS.

“This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device,” Cisco said in an advisory.

Cisco patched the vulnerability in early March, and in late July it updated the advisory for CVE-2026-20079 with indicators of compromise (IoCs). However, it did not explicitly warn about active exploitation at the time.

The tech giant updated its advisory again on September 9, saying that it became aware of the active exploitation of CVE-2026-20079 in August.

CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, instructing federal agencies to address it by September 12.

Advertisement. Scroll to continue reading.

Cisco FMC users can defend against attacks by installing the available patches. In addition, ensuring that the FMC interface cannot be accessed from the internet significantly reduces the risk of exploitation.

CVE-2026-20079 is the third FMC vulnerability added to CISA’s KEV list in 2026, after CVE-2026-20316 and CVE-2026-20131, which threat actors exploited as zero-days.

Attacks exploiting CVE-2026-20079 and CVE-2026-20316

Cisco’s Talos research and threat intelligence group reported on Wednesday that it’s aware of three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored threat actors and financially motivated groups.

One of the clusters, tracked by Talos as UAT-12197, exploited CVE-2026-20079 and deployed a web shell, which was used to deliver a malicious JAR file. This file then enabled the attacker to obtain user authentication data and credentials from the compromised system.

The second cluster is tracked as UAT-11823, which Talos has tied to the Russian APT known as Sandworm. This group exploited both FMC vulnerabilities and delivered the Cyclops Blink malware. 

The Cyclops Blink sample observed by Talos in these attacks enables its operator to download/upload files, harvest credentials, execute arbitrary files and commands, and scan the network. 

The third activity cluster is UAT-11988, believed to be connected to the Qilin ransomware. This threat actor exploited CVE-2026-20316 to gain access to targeted FMC devices, performing reconnaissance, stealing credentials, and creating a list of endpoints that can be targeted for encryption.

Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Related: MikroTik Patches Critical Flaws Chained to Hack Routers



Source link