Cisco FMC Bugs Exploited by Nation-State and Ransomware Operators

State-sponsored groups and ransomware operators are actively exploiting critical vulnerabilities within Cisco Secure Firewall Management Center software.

Cisco Talos threat intelligence analysts have confirmed active exploitation targeting two distinct security flaws in the Cisco Secure Firewall Management Center web interface: CVE-2026-20079 and CVE-2026-20316. CVE-2026-20079 is a critical authentication bypass stemming from an improper system process created at boot time, enabling remote unauthenticated attackers to execute commands and scripts providing root access via specially crafted HTTP requests. CVE-2026-20316, which was added to CISA’s Known Exploited Vulnerabilities catalog in July 2026, involves static hard-coded credentials for a low-privileged account that allows unauthorized remote login.

Investigators have identified three specific intrusion clusters leveraging these vulnerabilities. The first cluster utilizes CVE-2026-20079 to plant a malicious web shell in the CSM Tomcat webroot directory, followed by a malicious Java Archive file designed to capture user authentication data and system credentials. A second cluster, attributed to the Russian state-sponsored group Sandworm, gains initial access through either vulnerability, modifies the license.tmp file to establish a reverse command-and-control shell, harvests managed firewall configurations, and deploys multi-purpose network and packet-sniffing implants.

The third intrusion cluster is suspected to involve Qilin ransomware operators. These actors leverage the static credential flaw in CVE-2026-20316 to conduct endpoint and network reconnaissance, steal additional credentials, install persistence mechanisms, deploy antivirus-killing utilities, and execute ransomware payloads across compromised enterprise environments.

Cisco has released hotfixes for both vulnerabilities and strongly urges enterprise administrators to apply them immediately ahead of a comprehensive hardening package scheduled for release during the week of September 16, 2026. “Due to Talos identifying in the wild abuse of these CVE’s, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316,” researchers stated in an advisory. Alternatively, security teams can mitigate exposure by ensuring vulnerable FMC management interfaces are not accessible directly from the public internet.

Leave a Reply

Your email address will not be published. Required fields are marked *