Summary
- Cisco Talos has observed exploitation of CVE-2026-20079 and CVE-2026-20316 against Secure Firewall Management Center.
- CVE-2026-20079 can give an unauthenticated remote attacker root access to affected FMC systems.
- Talos identified post-compromise activity including credential theft, tunnelling, Cyclops Blink malware and Qilin ransomware deployment.
Cisco has confirmed active exploitation of two vulnerabilities in Secure Firewall Management Center, with compromises linked to state-sponsored activity and a ransomware operator.
Cisco Talos said on 9 September that attackers are abusing CVE-2026-20079 and CVE-2026-20316 against unpatched FMC systems. The platform centrally manages Cisco Secure Firewall deployments and occupies a privileged position inside network-security architecture.
CVE-2026-20079 is an authentication-bypass vulnerability carrying the maximum CVSS score of 10.0. Cisco says an unauthenticated remote attacker can exploit the flaw to bypass authentication and execute commands or scripts, ultimately obtaining root access to the underlying operating system.
CVE-2026-20316 has a lower CVSS score of 5.3 but can allow a remote attacker to log in using a low-privileged account and may be combined with other weaknesses to increase access.
Talos has identified three clusters of post-compromise activity. The first, tracked as UAT-12197, involved exploitation of CVE-2026-20079 followed by deployment of web shells, a Java-based command executor and credential-exfiltration tooling.
A second cluster, UAT-11823, combined the two vulnerabilities before attackers deployed reverse-shell and proxy tooling and ultimately a variant of Cyclops Blink. Previous versions of Cyclops Blink have been attributed by US and UK authorities to the Russian state-linked Sandworm group.
Talos attributed a third cluster, UAT-11988, with high confidence to a ransomware operator. That actor used static credentials to access FMC, mapped the surrounding environment, harvested credentials and established tunnelling infrastructure before activity consistent with Qilin ransomware affiliates culminated in ransomware deployment on selected endpoints.
The significance of compromising a firewall-management platform extends beyond control of the appliance. FMC contains configuration information and provides a central point from which organisations administer security policy across network boundaries. Successful compromise can therefore expose both privileged data and an unusually detailed view of how an enterprise environment is structured.
That creates an incident-response problem as well as an access problem. Firewalls and their management platforms are normally part of the infrastructure relied upon to contain an intrusion and reconstruct what occurred. Where the management plane itself has been compromised, responders have to determine whether policies, credentials and logs can still be trusted.
The attacks also show how vulnerabilities with different severity ratings can become more serious when combined. CVE-2026-20316 is not rated critical in isolation, but Talos observed it being used as part of intrusion chains that led to substantially broader access.
Cisco says hotfixes for both vulnerabilities are already available and is urging customers to deploy them without waiting for a wider hardening release expected during the week beginning 14 September.
There is a wider exposure-management issue in the persistence of vulnerable security appliances. Administrative interfaces often receive less visibility than conventional servers or endpoints despite holding comparable or greater privilege. Once internet-reachable management infrastructure becomes part of an active campaign, delays in remediation give attackers a route directly into the control plane intended to protect the rest of the network.
Talos’s findings make the exploitation status unambiguous. These are no longer vulnerabilities being assessed solely on theoretical impact: Cisco has documented their use in intrusions that progressed into credential theft, persistent access and, in at least one cluster, ransomware deployment.





