Download Privacy Needle App

Type to search

Cybersecurity

CISA Warns of Active Exploitation of Cisco Secure FMC Vulnerability

Share

Cisco and the Cybersecurity and Infrastructure Security Agency (CISA) have confirmed that threat actors are actively exploiting a critical vulnerability in the Cisco Secure Firewall Management Center (FMC).

The flaw, identified as CVE-2026-20079, is a critical authentication bypass issue. A remote, unauthenticated attacker can exploit the vulnerability to execute malicious scripts on affected devices, ultimately granting root access to the underlying operating system.

Threat Actor Activity and Malware Deployment

Research from Cisco’s Talos threat intelligence group has identified three distinct activity clusters leveraging this vulnerability. One cluster, tracked as UAT-12197, deploys a web shell to deliver malicious JAR files. These files are subsequently used to harvest user authentication data and credentials from the compromised system.

A second cluster, tracked as UAT-11823, has been linked to the Russian-based advanced persistent threat (APT) known as Sandworm. This group uses the vulnerability to deliver Cyclops Blink malware. Once deployed, the malware allows operators to download or upload files, execute arbitrary commands, and scan the internal network.

A third cluster, UAT-11988, is believed to be connected to the Qilin ransomware group. This actor exploits the flaw to perform reconnaissance, steal credentials, and identify specific endpoints to target for subsequent encryption.

CISA Response and Mitigation

CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalogue. Under this designation, federal agencies have been instructed to address the vulnerability by 12 September 2026.

The vulnerability is caused by an improper system process created during the boot sequence. Attackers can trigger the flaw by sending specifically crafted HTTP requests to an affected device.

Cisco released patches for the vulnerability in March 2026. Organisations using Cisco FMC should install the available updates immediately. Additionally, security teams can significantly reduce the risk of exploitation by ensuring the FMC interface is not accessible from the public internet.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.