Cisco Talos warned on September 9 that attackers are actively exploiting two Cisco Secure Firewall Management Center vulnerabilities in intrusions tied to advanced threat and ransomware activity. The more serious flaw, CVE-2026-20079, has a CVSS score of 10.0 and enables an unauthenticated remote attacker to gain root access. Talos documented three post-compromise clusters on unpatched FMC systems.

Cisco first published its CVE-2026-20079 advisory on March 4 and updated it on September 9 to confirm observed exploitation. The company said its Product Security Incident Response Team became aware of the activity in August. Talos also tracked abuse of CVE-2026-20316, a CVSS 5.3 static-credential flaw that permits remote access through a low-privileged account. BleepingComputer reported that CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog with a September 12 remediation deadline for federal civilian agencies.

According to Cisco, CVE-2026-20079 stems from an improper system process created at boot. Crafted HTTP requests sent to the FMC web interface can bypass authentication and run scripts or commands as root without user interaction. The flaw affects Cisco Secure FMC Software and Security Cloud Control Firewall Management regardless of configuration, although Cisco has already fixed the cloud-hosted service. Cisco said Firewall Device Manager, Secure Firewall ASA Software and Secure Firewall Threat Defense Software are not affected.

Talos linked the first cluster, UAT-12197, to exploitation of CVE-2026-20079 followed by a JSP web shell and a JAR-based command executor used to query internal databases for authentication data. A second cluster, UAT-11823, used a Netcat reverse shell and proxy tools before deploying a Cyclops Blink variant. Talos assessed with high confidence that UAT-11823 overlaps in tooling with the Russian Sandworm group, but did not state that the two are identical.

The third cluster, UAT-11988, was assessed by Talos with high confidence as a ransomware operator. The actor used access associated with CVE-2026-20316 and legitimate FMC tools to survey the victim environment, deploy tunnels, harvest credentials and identify endpoints for encryption or locking. Talos said the subsequent behavior was consistent with Qilin ransomware affiliates. Cisco advises administrators to examine system logs for package_info and license activity involving /var/tmp/license.tmp, which may indicate exploitation.

Cisco has issued hot fixes for supported FMC 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 releases and says no workaround addresses CVE-2026-20079. Administrators should apply the appropriate fixed release or hot fix, restrict public access to management interfaces and review the published indicators. Cisco cautions that its hot fixes prevent future exploitation but may not resolve an existing compromise; organizations finding indicators should contact Cisco Technical Assistance Center for recovery guidance.