# Cisco FMC RCE via CVE-2026-20079: Patch Now

> Active exploitation of critical Cisco Secure Firewall Management Center vulnerabilities (CVE-2026-20079, CVE-2026-20316) by state-sponsored and crimeware actors.

- Published: 2026-10-02T03:12:07.000Z
- Severity: critical
- Category: Vulnerabilities
- Tags: Sandworm, Ransomware, CVE-2026-20079, CVE-2026-20316, Cisco FMC
- CVEs: CVE-2026-20079 (CVSS 10), CVE-2026-20316 (CVSS 5.3)
- Author: Runtime Rebel Intel
- Primary source: https://blog.talosintelligence.com/fmc-ongoing-exploitation/
- Canonical: https://runtimerebel.com/blog/cisco-fmc-rce-via-cve-2026-20079-patch-now

## Key points

- Immediate impact: Unauthenticated attackers can gain root access to Cisco Secure Firewall Management Center instances through active exploitation.
- Affected systems: Unpatched instances of Cisco Secure Firewall Management Center (FMC) Software are vulnerable.
- Remediation: Apply the security patches and hotfixes released by Cisco for CVE-2026-20079 and CVE-2026-20316 immediately.

Cisco Talos has issued a critical warning regarding the active and ongoing exploitation of two significant vulnerabilities impacting Cisco Secure [Firewall](/glossary#firewall) Management Center (FMC) Software. These flaws, [CVE-2026-20079](/cve/cve-2026-20079) and [CVE-2026-20316](/cve/cve-2026-20316), are being leveraged by a range of threat actors, including state-sponsored groups and sophisticated crimeware operators, to gain unauthorized access and establish [persistence](/glossary#persistence) on affected devices, according to [Cisco Talos](https://blog.talosintelligence.com/fmc-ongoing-exploitation/).

## Overview of Cisco Secure Firewall Management Center Exploitation

At the core of these attacks is [CVE-2026-20079](https://nvd.nist.gov/vuln/detail/CVE-2026-20079), a critical authentication bypass [vulnerability](/glossary#vulnerability) with a [CVSS](/glossary#cvss) score of 10.0. This flaw allows an unauthenticated, remote attacker to bypass authentication mechanisms and execute arbitrary scripts on impacted FMC devices, ultimately achieving root access to the underlying operating system. Complementing this is [CVE-2026-20316](https://nvd.nist.gov/vuln/detail/CVE-2026-20316), which permits a remote attacker to log in with a low-privileged account. While less severe on its own (CVSS 5.3), this vulnerability can be chained with others for [privilege escalation](/glossary#privilege-escalation), as observed in current campaigns.

Organizations using Cisco FMC Software must prioritize patching these vulnerabilities immediately, as the window for unhindered exploitation is closing rapidly. Defenders should focus on `CVE-2026-20079 root access mitigation` as a primary concern.

### Technical Details of Exploitation Clusters

Cisco Talos has identified three distinct clusters of post-compromise activity associated with the exploitation of these vulnerabilities:

*   **Cluster #1: UAT-12197 (Crimeware)**
    This cluster primarily leverages [CVE-2026-20079](https://nvd.nist.gov/vuln/detail/CVE-2026-20079) to deploy malicious web shells (JSP-based) in the CSM Tomcat webroot directory. These web shells facilitate the placement of a Java Archive (JAR)-based command executor (`cmd.jar`) capable of querying internal databases for user authentication data and credentials using `OmniQuery.pl`.

*   **Cluster #2: UAT-11823 (State-Sponsored [APT](/glossary#apt))**
    Attributed with high confidence to UAT-11823, an advanced persistent threat (APT) actor showing tooling overlaps with the Russian APT [Sandworm](https://en.wikipedia.org/wiki/Sandworm), this cluster exploits both [CVE-2026-20079](https://nvd.nist.gov/vuln/detail/CVE-2026-20079) and [CVE-2026-20316](https://nvd.nist.gov/vuln/detail/CVE-2026-20316). After [initial access](/glossary#initial-access), attackers deploy a Netcat-based reverse shell by modifying the `license.tmp` file and executing it via `package_info.pl`. A significant finding in this cluster is the deployment of a modular ELF implant identified as a variant of `Cyclops Blink` [malware](/glossary#malware), previously linked to Sandworm. This variant boasts capabilities such as persistence, DNS over HTTPS (DoH) resolution, file administration, [credential harvesting](/glossary#credential-harvesting), arbitrary command execution, network scanning, and packet sniffing. Organizations must investigate any `Cyclops Blink malware detection Sandworm` indicators within their networks.

*   **Cluster #3: UAT-11988 ([Ransomware](/glossary#ransomware) Operator)**
    This cluster is attributed to a ransomware operator, UAT-11988, assessed with high confidence to be a Qilin ransomware affiliate. The attackers gain initial access, likely via static credentials enabled by [CVE-2026-20316](https://nvd.nist.gov/vuln/detail/CVE-2026-20316), then abuse legitimate built-in FMC tooling in a [living-off-the-land (LOTL)](/glossary#living-off-the-land-lotl) fashion. Their activities include extensive [reconnaissance](/glossary#reconnaissance), deployment of tunneling tools for persistent access, credential harvesting, and building target lists for [encryption](/glossary#encryption). Subsequent TTPs align with those observed in Qilin ransomware operations.

## Actionable Recommendations and Mitigations

Given the critical nature and active exploitation of these vulnerabilities, security professionals must take immediate action to protect their Cisco Secure Firewall Management Center deployments.

*   **Immediate Patching**: The most crucial step is to apply the hotfixes and security patches released by Cisco for [CVE-2026-20079](https://nvd.nist.gov/vuln/detail/CVE-2026-20079) and [CVE-2026-20316) immediately. Cisco has made these patches available, and a comprehensive hardening release is also expected.
*   **Monitor for Compromise Indicators**: Actively monitor FMC instances for signs of compromise, including unexpected file modifications in webroot directories, unusual process executions (e.g., `java -jar cmd.jar`, Netcat activity), or unauthorized user accounts. Specifically look for unusual activity related to `/var/jre/bin/java` and `/usr/local/sf/bin/package_info.pl`.
*   **Review Logs**: Analyze authentication and system logs for any anomalous logins, especially those using low-privileged accounts or originating from unfamiliar IP addresses. Regularly review access patterns to identify any deviations from the baseline.
*   **Network Segmentation**: Implement or reinforce network segmentation to limit the [blast radius](/glossary#blast-radius) in case of a successful compromise, restricting access to FMC devices only from trusted management networks.
*   **Credential Hygiene**: Ensure strong, unique credentials for all FMC accounts and consider implementing multi-factor authentication where possible, even for administrative interfaces.

The widespread and varied nature of these attacks underscores the urgency of addressing these Cisco FMC vulnerabilities. Proactive patching and vigilant monitoring are essential to prevent sophisticated threat actors from compromising critical network infrastructure.

**Related:** [Mount Royal University Data Breach: Ransomware Impact & Mitigation](/blog/mount-royal-university-data-breach-ransomware-impact-mitigation), [Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA](/blog/gunra-ransomware-exploits-fortinet-flaws-and-bypasses-mfa)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/cisco-fmc-rce-via-cve-2026-20079-patch-now
