Cisco, CISA warn of active exploitation of Secure FMC authentication bypass

This digest was compiled by AI from multiple sources — links to the originals are below.
Cisco and CISA on Wednesday flagged active exploitation of CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center. Cisco said it became aware of the attacks in August and updated its advisory on September 9. CISA added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by September 12.
Key Facts
- CVE-2026-20079 is a critical authentication bypass in Cisco Secure Firewall Management Center that allows unauthenticated remote attackers to execute scripts and gain root access.
- Cisco patched CVE-2026-20079 in early March 2026 and updated its advisory with indicators of compromise in late July.
- CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9, 2026, with a federal patch deadline of September 12.
- Cisco Talos identified three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including Sandworm and Qilin ransomware.
- CVE-2026-20316, a hard-coded credentials flaw in FMC, was disclosed and patched on July 29, 2026, and added to CISA's KEV catalog the same day.
Vulnerability Details
CVE-2026-20079 is an authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) software. It stems from an improper system process created at boot time and can be exploited by sending crafted HTTP requests to an affected device. A successful exploit allows a remote, unauthenticated attacker to execute script files and obtain root access to the underlying operating system. Cisco assigned the flaw a CVSS score of 10.0, the highest possible severity rating. Cisco patched CVE-2026-20079 in early March 2026 and later released indicators of compromise in late July.
Exploitation Activity
Cisco Talos reported three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored and financially motivated groups. Cluster UAT-12197 exploited CVE-2026-20079 to deploy a web shell and deliver a malicious JAR file that harvested user authentication data and credentials. Cluster UAT-11823, linked to the Russian APT Sandworm, exploited both vulnerabilities and delivered the Cyclops Blink malware. The Cyclops Blink sample observed by Talos enables file transfer, credential harvesting, command execution, and network scanning. Cluster UAT-11988, believed connected to Qilin ransomware, exploited CVE-2026-20316 for reconnaissance, credential theft, and endpoint targeting for encryption.
CISA Response
CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9, 2026. Federal Civilian Executive Branch agencies must apply patches by September 12, 2026. CISA also added CVE-2026-19490, a Citrix NetScaler authentication bypass, and CVE-2025-25249, a Fortinet FortiOS heap-based buffer overflow, to the KEV catalog. CVE-2026-20079 is the third FMC vulnerability added to CISA's KEV list in 2026, following CVE-2026-20316 and CVE-2026-20131.