Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially motivated attackers are actively exploiting CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC), using them to gain unauthenticated access and take control of affected systems. Cisco Talos identified three intrusion clusters tied to these flaws, including activity linked to Sandworm and a Qilin ransomware operator, and urges immediate hotfix deployment or restricting internet access to the FMC interface. #CVE-2026-20079 #CVE-2026-20316 #CiscoSecureFirewallManagementCenter #Sandworm #Qilin

Keypoints

  • CVE-2026-20079 allows remote unauthenticated attackers to gain root access through crafted HTTP requests.
  • CVE-2026-20316 lets attackers log in using static hard-coded credentials for a low-privileged account.
  • Cisco Talos is tracking three intrusion clusters using one or both FMC vulnerabilities.
  • Sandworm-linked activity used the flaws to deploy a reverse shell and steal firewall configuration data.
  • Qilin operators used CVE-2026-20316 for reconnaissance, credential theft, and ransomware deployment.

Read More: https://www.helpnetsecurity.com/2026/09/10/cisco-fmc-exploited-cve-2026-20079-cve-2026-20316/