Vulnerabilities

Organizations Warned of Cisco Secure FMC Exploitation

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Cisco vulnerability exploited

Cisco and the cybersecurity agency CISA on Wednesday flagged the exploitation of a Cisco Secure Firewall Management Center (FMC) vulnerability disclosed earlier this year.

The security hole, tracked as CVE-2026-20079, is a critical authentication bypass issue that a remote, unauthenticated attacker can exploit to run malicious scripts on vulnerable devices, enabling root access to the underlying OS.

“This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device,” Cisco said in an advisory.

Cisco patched the vulnerability in early March, and in late July it updated the advisory for CVE-2026-20079 with indicators of compromise (IoCs). However, it did not explicitly warn about active exploitation at the time.

The tech giant updated its advisory again on September 9, saying that it became aware of the active exploitation of CVE-2026-20079 in August.

CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, instructing federal agencies to address it by September 12.

Advertisement. Scroll to continue reading.

Cisco FMC users can defend against attacks by installing the available patches. In addition, ensuring that the FMC interface cannot be accessed from the internet significantly reduces the risk of exploitation.

CVE-2026-20079 is the third FMC vulnerability added to CISA’s KEV list in 2026, after CVE-2026-20316 and CVE-2026-20131, which threat actors exploited as zero-days.

Attacks exploiting CVE-2026-20079 and CVE-2026-20316

Cisco’s Talos research and threat intelligence group reported on Wednesday that it’s aware of three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored threat actors and financially motivated groups.

One of the clusters, tracked by Talos as UAT-12197, exploited CVE-2026-20079 and deployed a web shell, which was used to deliver a malicious JAR file. This file then enabled the attacker to obtain user authentication data and credentials from the compromised system.

The second cluster is tracked as UAT-11823, which Talos has tied to the Russian APT known as Sandworm. This group exploited both FMC vulnerabilities and delivered the Cyclops Blink malware. 

The Cyclops Blink sample observed by Talos in these attacks enables its operator to download/upload files, harvest credentials, execute arbitrary files and commands, and scan the network. 

The third activity cluster is UAT-11988, believed to be connected to the Qilin ransomware. This threat actor exploited CVE-2026-20316 to gain access to targeted FMC devices, performing reconnaissance, stealing credentials, and creating a list of endpoints that can be targeted for encryption.

Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Related: MikroTik Patches Critical Flaws Chained to Hack Routers

Related Content

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Mobile & Wireless

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

Vulnerabilities

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.

Vulnerabilities

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.

Network Security

Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass.

ICS/OT

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Vulnerabilities

The security defect allows remote attackers to bypass authentication through argument bearer manipulation.

Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version