Three Threat Groups Exploit Cisco Firewall Manager Flaws, Including CVSS 10.0 Bug
Cisco Talos confirmed on September 9, 2026, that two vulnerabilities in Cisco Secure Firewall Management Center (FMC) were being actively exploited by three distinct threat clusters. The more severe flaw, CVE-2026-20079 (CVSS 10.0), allows an unauthenticated attacker to bypass login and execute commands as root via a crafted HTTP request, while CVE-2026-20316 (CVSS 5.3) involves hardcoded credentials enabling limited unauthorized access. A suspected Sandworm-linked group chained both flaws to install a Cyclops Blink malware variant, a credential thief deployed a web shell to extract authentication data, and a Qilin ransomware affiliate used the static credentials to map networks and deploy ransomware. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog the same day, setting a federal remediation deadline of September 12, 2026. Because FMC centrally manages firewall policy and configuration across entire network estates, its compromise effectively undermines the security of every device it controls.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in