Cisco Talos has issued a critical warning regarding the active and ongoing exploitation of two significant vulnerabilities impacting Cisco Secure Firewall Management Center (FMC) Software. These flaws, CVE-2026-20079 and CVE-2026-20316, are being leveraged by a range of threat actors, including state-sponsored groups and sophisticated crimeware operators, to gain unauthorized access and establish persistence on affected devices, according to Cisco Talos.
Overview of Cisco Secure Firewall Management Center Exploitation
At the core of these attacks is CVE-2026-20079, a critical authentication bypass vulnerability with a CVSS score of 10.0. This flaw allows an unauthenticated, remote attacker to bypass authentication mechanisms and execute arbitrary scripts on impacted FMC devices, ultimately achieving root access to the underlying operating system. Complementing this is CVE-2026-20316, which permits a remote attacker to log in with a low-privileged account. While less severe on its own (CVSS 5.3), this vulnerability can be chained with others for privilege escalation, as observed in current campaigns.
Organizations using Cisco FMC Software must prioritize patching these vulnerabilities immediately, as the window for unhindered exploitation is closing rapidly. Defenders should focus on CVE-2026-20079 root access mitigation as a primary concern.
Technical Details of Exploitation Clusters
Cisco Talos has identified three distinct clusters of post-compromise activity associated with the exploitation of these vulnerabilities:
-
Cluster #1: UAT-12197 (Crimeware) This cluster primarily leverages CVE-2026-20079 to deploy malicious web shells (JSP-based) in the CSM Tomcat webroot directory. These web shells facilitate the placement of a Java Archive (JAR)-based command executor (
cmd.jar) capable of querying internal databases for user authentication data and credentials usingOmniQuery.pl. -
Cluster #2: UAT-11823 (State-Sponsored APT) Attributed with high confidence to UAT-11823, an advanced persistent threat (APT) actor showing tooling overlaps with the Russian APT Sandworm, this cluster exploits both CVE-2026-20079 and CVE-2026-20316. After initial access, attackers deploy a Netcat-based reverse shell by modifying the
license.tmpfile and executing it viapackage_info.pl. A significant finding in this cluster is the deployment of a modular ELF implant identified as a variant ofCyclops Blinkmalware, previously linked to Sandworm. This variant boasts capabilities such as persistence, DNS over HTTPS (DoH) resolution, file administration, credential harvesting, arbitrary command execution, network scanning, and packet sniffing. Organizations must investigate anyCyclops Blink malware detection Sandwormindicators within their networks. -
Cluster #3: UAT-11988 (Ransomware Operator) This cluster is attributed to a ransomware operator, UAT-11988, assessed with high confidence to be a Qilin ransomware affiliate. The attackers gain initial access, likely via static credentials enabled by CVE-2026-20316, then abuse legitimate built-in FMC tooling in a living-off-the-land (LOTL) fashion. Their activities include extensive reconnaissance, deployment of tunneling tools for persistent access, credential harvesting, and building target lists for encryption. Subsequent TTPs align with those observed in Qilin ransomware operations.
Actionable Recommendations and Mitigations
Given the critical nature and active exploitation of these vulnerabilities, security professionals must take immediate action to protect their Cisco Secure Firewall Management Center deployments.
- Immediate Patching: The most crucial step is to apply the hotfixes and security patches released by Cisco for CVE-2026-20079 and [CVE-2026-20316) immediately. Cisco has made these patches available, and a comprehensive hardening release is also expected.
- Monitor for Compromise Indicators: Actively monitor FMC instances for signs of compromise, including unexpected file modifications in webroot directories, unusual process executions (e.g.,
java -jar cmd.jar, Netcat activity), or unauthorized user accounts. Specifically look for unusual activity related to/var/jre/bin/javaand/usr/local/sf/bin/package_info.pl. - Review Logs: Analyze authentication and system logs for any anomalous logins, especially those using low-privileged accounts or originating from unfamiliar IP addresses. Regularly review access patterns to identify any deviations from the baseline.
- Network Segmentation: Implement or reinforce network segmentation to limit the blast radius in case of a successful compromise, restricting access to FMC devices only from trusted management networks.
- Credential Hygiene: Ensure strong, unique credentials for all FMC accounts and consider implementing multi-factor authentication where possible, even for administrative interfaces.
The widespread and varied nature of these attacks underscores the urgency of addressing these Cisco FMC vulnerabilities. Proactive patching and vigilant monitoring are essential to prevent sophisticated threat actors from compromising critical network infrastructure.
Related: Mount Royal University Data Breach: Ransomware Impact & Mitigation, Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA