Cisco FMC Flaws Actively Exploited by Threat Actors
Cisco has issued hotfixes for two critical vulnerabilities in its Secure Firewall Management Center (FMC) Software, which are being actively exploited by threat actors to gain root access and deploy malware.
The most severe issue is an authentication-bypass vulnerability, CVE-2026-20079, with a CVSS score of 10.0. This allows an unauthenticated remote attacker to bypass FMC authentication controls and execute scripts on compromised systems, potentially gaining root access to the underlying operating system.
Talos has identified three distinct clusters of post-compromise activities linked to state-sponsored and financially motivated actors. The first cluster exploited CVE-2026-20079 to deploy a JSP web shell and command executor, while the second cluster attributed to an advanced persistent threat actor replaced license.tmp with a malicious Makeself package.
Cisco urged affected organizations to deploy the hotfixes immediately and monitor for suspicious use of package_info.pl, unexpected files in Tomcat directories, outbound reverse-shell traffic, and new persistence scripts located in /etc/init.d/. The company also plans to release a broader hardening update on September 14.