Cisco FMC Critical Auth Bypass Exploited by Espionage, Ransomware Groups
A critical authentication bypass vulnerability (CVE-2026-20079, CVSS 10.0) in Cisco's Firewall Management Center allows unauthenticated attackers to execute commands with root privileges by sending a crafted HTTP request to the web interface. Cisco first patched and disclosed the flaw in March 2026, but active exploitation was observed in August 2026 and confirmed by Cisco Talos on 9 September 2026. Three distinct threat clusters exploited the vulnerability, including a group linked to Russian state-sponsored Sandworm deploying a Cyclops Blink variant, and a Qilin ransomware affiliate that used a chained secondary flaw to harvest credentials and encrypt endpoints. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 9 September 2026, setting a federal remediation deadline of 12 September 2026. The incident highlights the outsized risk posed by exposed management consoles, as compromising FMC grants attackers control over every firewall the platform manages.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in