CISA Warns of Active Exploitation of Cisco Secure FMC Vulnerability
Share
Cisco and the Cybersecurity and Infrastructure Security Agency (CISA) have confirmed that threat actors are actively exploiting a critical vulnerability in the Cisco Secure Firewall Management Center (FMC).
The flaw, identified as CVE-2026-20079, is a critical authentication bypass issue. A remote, unauthenticated attacker can exploit the vulnerability to execute malicious scripts on affected devices, ultimately granting root access to the underlying operating system.
Threat Actor Activity and Malware Deployment
Research from Cisco’s Talos threat intelligence group has identified three distinct activity clusters leveraging this vulnerability. One cluster, tracked as UAT-12197, deploys a web shell to deliver malicious JAR files. These files are subsequently used to harvest user authentication data and credentials from the compromised system.
A second cluster, tracked as UAT-11823, has been linked to the Russian-based advanced persistent threat (APT) known as Sandworm. This group uses the vulnerability to deliver Cyclops Blink malware. Once deployed, the malware allows operators to download or upload files, execute arbitrary commands, and scan the internal network.
A third cluster, UAT-11988, is believed to be connected to the Qilin ransomware group. This actor exploits the flaw to perform reconnaissance, steal credentials, and identify specific endpoints to target for subsequent encryption.
CISA Response and Mitigation
CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalogue. Under this designation, federal agencies have been instructed to address the vulnerability by 12 September 2026.
The vulnerability is caused by an improper system process created during the boot sequence. Attackers can trigger the flaw by sending specifically crafted HTTP requests to an affected device.
Cisco released patches for the vulnerability in March 2026. Organisations using Cisco FMC should install the available updates immediately. Additionally, security teams can significantly reduce the risk of exploitation by ensuring the FMC interface is not accessible from the public internet.




Leave a Reply